Full Report
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that host their own gateway need to act. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. The flaw
Analysis Summary
# Vulnerability: GitLab AI Gateway Remote Command Execution via Template Injection
## CVE Details
- **CVE ID:** CVE-2026-90970
- **CVSS Score:** 9.9 (Critical)
- **CWE:** CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine)
## Affected Systems
- **Products:** GitLab AI Gateway (Self-hosted instances)
- **Versions:**
- 18.1.6 through 19.2.3
- 19.3.x prior to 19.3.2
- 19.4.x prior to 19.4.1
- **Configurations:** Only organizations that host their own AI Gateway (Docker or Helm chart deployments) are affected. GitLab-hosted gateways (GitLab.com and GitLab Dedicated) have already been patched by the vendor.
## Vulnerability Description
A critical flaw exists in the prompt template of a "custom flow" within GitLab's Duo Agent Platform. The vulnerability allows a logged-in user with Duo Agent Platform access to escape the prompt template sandbox using a specially crafted flow configuration. This results in an arbitrary command execution on the gateway service, which manages sensitive JSON Web Tokens (JWT) and connections to AI model providers.
## Exploitation
- **Status:** Not exploited (CISA assessment lists exploitation as "none" as of October 2).
- **Complexity:** Medium (Requires Duo Agent Platform access and a specially crafted flow configuration).
- **Attack Vector:** Network (Authenticated).
## Impact
- **Confidentiality:** High (Potential access to signing keys and AI request/response data).
- **Integrity:** High (Ability to execute arbitrary commands on the gateway).
- **Availability:** High (Potential for service disruption).
## Remediation
### Patches
GitLab recommends upgrading self-hosted AI Gateways to the following versions immediately:
- **19.2.4**
- **19.3.2**
- **19.4.1**
*Note: Admins using Docker should pull the new image tag (e.g., `self-hosted-v19.4.1-ee`), and Helm users should update the image tag in their chart settings.*
### Workarounds
- No official workarounds have been provided. Organizations unable to patch should consider restricting access to the Duo Agent Platform or temporarily disabling self-hosted gateway services.
## Detection
- **Indicators of Compromise:** Unusual activity in the AI Gateway logs, specifically regarding "custom flow" configurations or sandbox escape attempts.
- **Detection methods and tools:** Audit GitLab Duo Agent Platform logs for unauthorized or highly complex flow definitions created by users. Monitor for unexpected process execution on the AI Gateway container/host.
## References
- GitLab Advisory: [https[:]//docs[.]gitlab[.]com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/](https[:]//docs[.]gitlab[.]com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/)
- CVE Record: [https[:]//github[.]com/CVEProject/cvelistV5/blob/main/cves/2026/90xxx/CVE-2026-90970[.]json](https[:]//github[.]com/CVEProject/cvelistV5/blob/main/cves/2026/90xxx/CVE-2026-90970[.]json)
- GitLab Upgrade Guide: [https[:]//docs[.]gitlab[.]com/install/install_ai_gateway/#upgrade-the-ai-gateway-docker-image](https[:]//docs[.]gitlab[.]com/install/install_ai_gateway/#upgrade-the-ai-gateway-docker-image)