GitLab — Critical Command Execution Patch for AI Gateway (CVE-2026-90970)

Publication date: October 02, 2026
Category: Vulnerability / Application Security

Introduction

GitLab has issued critical security advisories to remediate a high-severity vulnerability tracked as CVE-2026-90970 (with a CVSS score of 9.9) affecting the GitLab AI Gateway component. Discovered by HackerOne researcher invisiblemeerkat, the flaw impacts self-hosted instances of the AI gateway. Under specific conditions, it allows an authenticated user with Duo Agent Platform privileges to execute arbitrary commands on the underlying server through specially crafted flow configurations.


What is GitLab AI Gateway? (General Analysis)

The GitLab AI Gateway is the intermediate service responsible for connecting a GitLab instance with various large language models and artificial intelligence providers. Its core architecture processes requests and responses related to productivity tools such as GitLab Duo.

For organizations that require strict adherence to data privacy mandates regarding model training and telemetry, GitLab provides an option to deploy their own gateway locally or within private infrastructure. However, because this component handles automated processing logic and sensitive credentials — including JSON Web Token (JWT) signing keys and external model integrations — it represents a high-value attack surface.

Vulnerability Data

  • CVE-2026-90970 (NVD Verified):

    • CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • Score: 9.9 (CRITICAL)
    • CWE Classification: CWE-1336 (Improper Control of Generation of Code / Template Injection)
    • CISA KEV: Not reported in the catalog as of publication date.
  • CVE-2026-1868 (Historical NVD Verified Precedent):

    • CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
    • Score: 9.9 (CRITICAL)
    • CWE Classification: CWE-1336

How Does It Work? (Technical Analysis)

The technical flaw stems from insecure handling of prompt templates within custom workflows inside the Duo Agent Platform, which allows users to automate multi-step tasks using AI.

  • Initial Exploit Entry Flow: An attacker with authenticated access to the agent platform generates or modifies a Duo Agent Platform Flow definition using a maliciously structured template configuration.
  • Sandbox Escape and Code Execution: During the expansion of user-supplied data within the template engine, internal validation fails to properly restrict the execution context. This triggers a breakout from the secure template sandbox, enabling template injection and subsequent arbitrary command execution on the gateway’s operating system.
  • Credential Exposure: Because a self-hosted gateway retains authentication tokens and external model provider credentials, successful exploitation jeopardizes the confidentiality and integrity of the entire connected infrastructure.

Affected Systems / Environments

The impact is strictly limited to organizations operating their own self-hosted AI Gateway infrastructure. Customers managed directly by GitLab in cloud or dedicated environments (GitLab.com and GitLab Dedicated) received centralized mitigations prior to public disclosure.

Affected Versions and Patches Matrix

CVE Affected AI Gateway Versions Initial Patched Version
CVE-2026-90970 18.1.6 up to 19.2.4 (excl.)
19.3 up to 19.3.2 (excl.)
19.4 up to 19.4.1 (excl.)
19.2.4, 19.3.2, 19.4.1
CVE-2026-1868 18.1.6, 18.2.6, 18.3.1 through 18.6.1, 18.7.0, 18.8.0 18.6.2, 18.7.1, 18.8.1

Mitigation and Detection

Remediation

Administrators running self-hosted instances must immediately upgrade the AI Gateway component to the patched versions corresponding to their active support line (19.2.4, 19.3.2, or 19.4.1).

  • Docker Deployments: Stop and remove the running container, pull the updated image tag, and restart the service (e.g., self-hosted-v19.4.1-ee).
  • Helm Chart Deployments: Update the image tag parameter in the Helm chart configuration.

Operational Warning: As no workarounds are currently available for instances unable to update immediately, applying the official software updates remains the sole effective mitigation path.

Detection

Incident response teams and SOC analysts should focus monitoring efforts on:

  • Inspecting AI Gateway access logs for unusual request patterns or suspicious bulk modifications to Duo Agent Platform flow definitions.
  • Monitoring for unexpected child processes spawned by the gateway container or service (such as unauthorized shell interpreters like sh, bash, python, or anomalous network connections).

Wrapping Up

The identification and patching of CVE-2026-90970 highlight inherent security risks associated with integrating dynamic template engines into modern artificial intelligence platforms. The ability to escape a sandbox via manipulated flow configurations demonstrates that AI-driven automation interfaces require rigorous input sanitization controls. Organizations maintaining self-hosted deployments of GitLab AI Gateway must prioritize these security updates to mitigate the risk of remote command execution.


References