TL;DR
GitLab released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970. The GitLab AI Gateway vulnerability scores 9.9 on CVSS 3.1. It lets a logged-in Duo Agent Platform user run arbitrary commands on self-hosted gateways.
- CVE: CVE-2026-90970
- CVSS: 9.9 (Critical · CVSSv3)
- Product: GitLab AI Gateway
- Affected: 18.1.6, 19.3, 19.4
- Impact: Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
- Status: No confirmed exploitation yet
- Patched in: 19.2.4, 19.3.2, 19.4.1
- Action: Update to 19.2.4, 19.3.2, 19.4.1 now
See a GitLab CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy It Matters
The AI Gateway sits between GitLab and the AI models behind GitLab Duo. A takeover could expose prompts, code, and model credentials that pass through it. Only one condition stands in the way: the attacker needs Duo Agent Platform access. GitLab rates this GitLab AI Gateway vulnerability as critical, and its CVSS vector marks a scope change beyond the gateway itself.
So far, no exploitation in the wild has been confirmed. No public proof-of-concept exists, and the flaw is not in CISA’s KEV catalog. GitLab does not publish counts of self-hosted gateway installs.
How the Attack Works
The bug lives in custom flow prompt templates. GitLab says an authenticated user could “escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.” TheHackerWire classifies it as server-side template injection (CWE-1336). The researcher invisiblemeerkat reported the issue.
Affected Versions
- 18.1.6 up to, but not including, 19.2.4
- 19.3 before 19.3.2
- 19.4 before 19.4.1
Only self-hosted deployments need action. GitLab already fixed its hosted gateways. As a result, customers on GitLab.com, GitLab Dedicated, and Self-Managed instances that use a GitLab-hosted AI Gateway are protected.
Patch and Mitigation Steps
GitLab urges admins to upgrade every affected GitLab Self-Hosted AI Gateway “as soon as possible.” It also contacted those customers before publishing the GitLab AI Gateway 19.4.1 patch release notes. Until upgrades finish, teams should review who holds Duo Agent Platform access. This step narrows exposure to the GitLab AI Gateway vulnerability.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!