GitLab has issued an urgent security advisory addressing a critical vulnerability within its AI Gateway component, a service that facilitates the integration of artificial intelligence models into the GitLab development ecosystem. Identified as CVE-2026-90970, the flaw carries a CVSS score of 9.9, marking it as a high-severity risk that could permit authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the underlying gateway infrastructure.
The vulnerability stems from a weakness in the prompt template logic within the Duo Agent Platform’s custom workflow engine. By manipulating a specially crafted flow configuration, an attacker can effectively bypass the intended sandbox protections, leading to remote code execution (RCE). The discovery of this vulnerability highlights the expanding attack surface created by the rapid integration of AI-driven tools into enterprise development pipelines.
Scope of the Vulnerability and Affected Deployments
The critical nature of this disclosure is tempered by the specific deployment models impacted. Organizations utilizing GitLab’s cloud-hosted services—specifically GitLab.com, GitLab Dedicated, and self-managed instances that rely on GitLab-managed AI Gateways—are not required to take immediate action, as these environments have already been patched by GitLab’s security operations team.
However, the risk is significant for organizations that have opted to self-host the AI Gateway. This configuration is often preferred by enterprises with strict data residency requirements, as it allows AI request and response data to remain within the internal network perimeter. For these self-hosted users, the gateway functions as a critical bridge between internal assets and external AI model providers, holding sensitive credentials such as JSON Web Tokens (JWT) and API keys. Compromise of this gateway could potentially grant an attacker a foothold within the organization’s secure development environment.
Technical Breakdown: CVE-2026-90970
The vulnerability is categorized under CWE-1336, which refers to "Improper Neutralization of Special Elements Used in a Template Engine." This indicates that the AI Gateway’s template engine fails to properly sanitize input, allowing a user to inject malicious code through a custom flow definition.

When a user with Duo Agent Platform access creates a multi-step automated task, the system processes the configuration via the gateway. If that configuration is malicious, the gateway interprets the instructions in a way that escapes the secure environment, executing the command at the privilege level of the gateway service itself. While the exact conditions required for successful exploitation remain partially obscured, the potential for unauthorized code execution poses a severe threat to the integrity of the GitLab instance and any connected systems.
Remediation and Patch Chronology
GitLab has moved quickly to release patches for the affected versions. The fix is available in versions 19.2.4, 19.3.2, and 19.4.1. The following table details the remediation path for administrators currently running vulnerable deployments:
| Current Gateway Version | Required Fixed Version |
|---|---|
| 18.1.6 to 19.2.3 | 19.2.4 |
| 19.3.0 to 19.3.1 | 19.3.2 |
| 19.4.0 | 19.4.1 |
For administrators managing these deployments via Docker or Helm, the update process is non-trivial. It requires stopping and removing existing containers before pulling the updated images (e.g., self-hosted-v19.4.1-ee) or updating the tag configuration in the Helm chart. Given that no formal workaround exists, the only viable path for remediation is the immediate application of these patches.
Industry Context and Historical Vulnerabilities
This is not the first instance of a critical flaw appearing in the AI Gateway. In February 2026, GitLab patched CVE-2026-1868, a vulnerability that also received a 9.9 CVSS score. That incident similarly involved a template engine weakness that allowed authenticated users to trigger code execution through crafted flow definitions.
The recurrence of CWE-1336 vulnerabilities within the same component suggests a systemic challenge in securing the interface between user-defined AI workflows and the underlying execution engine. As organizations shift toward agentic AI workflows—where agents are granted the authority to perform tasks autonomously—the security of the "prompt engineering" and "workflow configuration" layers becomes as critical as traditional binary security.
Security Implications for Enterprise Environments
The implications of CVE-2026-90970 extend beyond the immediate risk of system compromise. Self-hosted AI Gateways often function as central hubs for an organization’s AI interactions. If an attacker gains command execution on these nodes, they could potentially intercept sensitive proprietary code, exfiltrate API keys used for AI model authentication, or pivot into other segments of the internal network.

Furthermore, the lack of information regarding historical exploitation—coupled with the CISA assessment that current exploitation is "none"—should not be viewed as a signal for complacency. Critical vulnerabilities of this nature are prime targets for automated exploit development. The fact that the vulnerability was reported through the HackerOne bug bounty program, credited to a researcher under the handle "invisiblemeerkat," underscores the importance of robust vulnerability disclosure programs in identifying high-impact flaws before they reach the hands of malicious actors.
Strategic Considerations for Security Teams
For security operations centers (SOCs) and IT administrators, this event serves as a reminder of the "shadow IT" risks inherent in adopting new AI technologies. While the AI Gateway provides a necessary convenience for integrating LLMs into DevOps, it introduces a new class of potential vulnerabilities.
- Inventory Management: Organizations must maintain an accurate inventory of all self-hosted AI components. Because the AI Gateway is often deployed independently of the primary GitLab instance, it can easily be overlooked during routine patch cycles.
- Access Control: The vulnerability requires "Duo Agent Platform access." Security teams should audit their internal user permissions to ensure that only authorized personnel have the ability to configure or deploy custom flows within the AI Gateway.
- Monitoring and Logging: Because the advisory does not offer a method to detect prior exploitation, teams should perform an immediate audit of their AI Gateway logs. While retrospective analysis may be difficult, identifying unusual outbound traffic or unauthorized process execution from the gateway container may provide indicators of compromise.
- Patching Velocity: The rapid release cycle of AI tools necessitates a shift in patching strategy. Organizations should prioritize the automated deployment of security updates for containerized services to reduce the window of exposure.
Future Outlook and Conclusion
The landscape of software supply chain security is rapidly evolving to encompass the unique risks posed by artificial intelligence. As GitLab continues to push the boundaries of AI-assisted software development, the security of its infrastructure will remain a top priority for its global user base.
CVE-2026-90970 highlights a crucial lesson for the software development industry: security cannot be bolted onto AI features as an afterthought. It must be integrated into the architecture of the workflow engines themselves. The "template engine" class of vulnerabilities is particularly dangerous because it blurs the line between legitimate configuration and malicious execution.
GitLab has demonstrated a commitment to transparency by disclosing the flaw and providing clear upgrade paths. For the self-hosted user community, the priority remains clear: ensure that the AI Gateway is updated to the latest secure version, verify internal access controls, and maintain a vigilant watch for anomalous behavior within the gateway’s environment. As organizations continue to rely on AI-driven development tools, the ability to rapidly respond to such vulnerabilities will become a defining characteristic of a resilient security posture.
The absence of public exploitation at this time is a fortunate circumstance, but it provides only a brief window for remediation. Security administrators are encouraged to treat the update to version 19.4.1 or the relevant fixed branch as a high-priority task, ensuring that their AI-integrated pipelines remain a catalyst for productivity rather than a vector for potential compromise.
