Full Report
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
Analysis Summary
# Vulnerability: GitLab AI Gateway Remote Code Execution (RCE)
## CVE Details
- **CVE ID:** CVE-2026-90970
- **CVSS Score:** 9.9 (Critical - *estimated based on vendor advisory description*)
- **CWE:** CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine)
## Affected Systems
- **Products:** GitLab Self-Hosted AI Gateway (Duo Self-Hosted)
- **Versions:**
- Versions prior to 19.2.4
- Versions prior to 19.3.2
- Versions prior to 19.4.1
- **Configurations:** Systems running GitLab Self-Managed with self-hosted AI Gateway instances. **Note:** GitLab-hosted AI Gateway (SaaS/Dedicated) instances have already been patched by the vendor.
## Vulnerability Description
The vulnerability exists due to an improper neutralization flaw within the AI Gateway's prompt template sandbox. Under specific conditions, an authenticated user with Duo Agent Platform access can bypass sandbox restrictions via a specially crafted flow configuration. This escape allows the attacker to execute arbitrary commands on the underlying AI Gateway instance.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; however, GitLab has conducted targeted outreach, suggesting a high risk of weaponization.
- **Complexity:** Low (requires specific flow configuration).
- **Attack Vector:** Network (Authenticated).
## Impact
- **Confidentiality:** Critical (Full access to data processed by the AI Gateway).
- **Integrity:** Critical (Ability to execute arbitrary commands and modify system configurations).
- **Availability:** Critical (Potential for complete system takeover or service disruption).
## Remediation
### Patches
GitLab strongly recommends that all Self-Managed customers update their AI Gateway Docker images to the following versions immediately:
- **19.2.4**
- **19.3.2**
- **19.4.1**
### Workarounds
There are no official workarounds provided. Remediation requires updating the AI Gateway to a patched version.
## Detection
- **Indicators of Compromise:** Monitor for unusual flow configurations within GitLab Duo or unexpected outbound network traffic from the AI Gateway container/host.
- **Detection methods:** Review AI Gateway logs for sandbox escape attempts or unauthorized shell command execution (e.g., `exec` calls).
## References
- **Vendor Advisory:** [hxxps://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/](hxxps://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/)
- **NVD Entry:** [hxxps://nvd.nist.gov/vuln/detail/cve-2026-90970](hxxps://nvd.nist.gov/vuln/detail/cve-2026-90970)
- **Upgrade Guidance:** [hxxps://docs.gitlab.com/install/install_ai_gateway/#upgrade-the-ai-gateway-docker-image](hxxps://docs.gitlab.com/install/install_ai_gateway/#upgrade-the-ai-gateway-docker-image)