GitLab Patches AI Gateway Sandbox Escape CVE-2026-90970, Rated 9.9
Security / news
GitLab Patches AI Gateway Sandbox Escape CVE-2026-90970, Rated 9.9
The fix reaches self-hosted AI Gateway operators in versions 19.2.4, 19.3.2 and 19.4.1, and an attacker needs a Duo Agent Platform login first.

GitLab patched CVE-2026-90970, a command-execution flaw in its self-hosted AI Gateway rated 9.9 out of 10 on the CVSS severity scale, on Oct. 2 with versions 19.2.4, 19.3.2 and 19.4.1.
The attacker needs an authenticated account with access to the Duo Agent Platform. GitLab said the flaw "could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration", according to BleepingComputer and Security Affairs, which quote the same sentence. The result is arbitrary command execution on the gateway host.
Which AI Gateway versions are affected
Security Affairs lists three affected ranges, each with its own fix.
| Affected AI Gateway versions | Fixed in |
|---|---|
| 18.1.6 through 19.2.3 | 19.2.4 |
| 19.3.0 through 19.3.1 | 19.3.2 |
| 19.4.0 | 19.4.1 |
The flaw sits in how the gateway handles custom flow prompt templates. A prompt template sandbox is meant to let users supply template logic without letting that logic reach the host; this bug let a crafted flow configuration cross that line.
The affected range starts at 18.1.6 and ends at 19.4.0, so it spans both the 18.x and 19.x lines. By the table above, a gateway on 19.3.1 is vulnerable and the listed fix for its branch is 19.3.2. A gateway on 18.1.5 falls outside the range Security Affairs gives, and the sources do not say whether earlier builds had the same weakness.

Who has to patch
GitLab-hosted instances were already patched, and BleepingComputer reports that no action is needed there. The operators at risk are those running their own AI Gateway. GitLab did targeted outreach to self-hosted customers before the public disclosure on Oct. 2, per the same report.
What the score does and does not say
The precondition is a valid login with Duo Agent Platform rights, so the 9.9 describes the impact (commands on the gateway host) more than the ease of attack. Neither article we read prints the CVSS vector, so the reason for a 9.9 rather than a lower figure for a login-gated flaw cannot be checked from them.
Security Affairs reports no evidence of exploitation in the wild and no public proof of concept. It credits a HackerOne researcher using the handle invisiblemeerkat with the report.
A September GitLab flaw is already on CISA's list
BleepingComputer places the bug after a September path traversal flaw, CVE-2026-85706, that CISA added to its exploited-vulnerabilities list. The report calls this at least the second critical GitLab vulnerability since then.
Sandbox boundaries around agent code are the subject of other projects we have covered, including NVIDIA's OpenShell agent sandbox and Google's donation of gVisor to the CNCF. GitLab's flaw is a template sandbox rather than a runtime one, so the comparison is about where the boundary sits, not the code.
Self-hosted operators should check the gateway version against 19.2.4, 19.3.2 and 19.4.1 and upgrade the matching branch. Operators who cannot upgrade immediately have no workaround in either article, which leaves removing Duo Agent Platform access from untrusted users as the only control the reporting supports.
Sources
More in Security
- 01NetScaler CVE-2026-88779 Is Rated Denial of Service, but a Researcher Reports a Payload DownloadCitrix patched a SAML memory overflow on October 3 and 4 after attacks began. CISA gave agencies until October 7, and the appliances patched last week for CVE-2026-88771 through CVE-2026-88778 need updating again.
- 02Cisco SD-WAN Manager Flaw CVE-2026-76504 Needs One Encoded Character for Admin API Access, With No WorkaroundCisco's PSIRT found exploitation during a support case in September. Six release trains have fixes, and the vendor and two security firms count Cisco's earlier SD-WAN flaws differently.
- 03Two Zammad Zero-Days Took an Attacker From Session Hijack to Root at the Dutch Institute for Vulnerability DisclosureCISA put CVE-2026-102489 and CVE-2026-102490 in its exploited catalog on October 2. DIVD says an AI agent, not a person, ran the intrusion it found on its own ticketing system.
- 04Citrix NetScaler Zero-Days Are Exploited Without Credentials, and Web Shells Survive the PatchCVE-2026-88771 and CVE-2026-88772 both score 9.5. Citrix shipped fixed builds on September 27, but researchers say implants planted earlier persist through the update.