GitLab — Critical Command Execution Patch for AI Gateway (CVE-2026-90970)
Publication date: October 02, 2026
Category: Vulnerability / Application Security
Introduction
GitLab has issued critical security advisories to remediate a high-severity vulnerability tracked as CVE-2026-90970 (with a CVSS score of 9.9) affecting the GitLab AI Gateway component. Discovered by HackerOne researcher invisiblemeerkat, the flaw impacts self-hosted instances of the AI gateway. Under specific conditions, it allows an authenticated user with Duo Agent Platform privileges to execute arbitrary commands on the underlying server through specially crafted flow configurations.
What is GitLab AI Gateway? (General Analysis)
The GitLab AI Gateway is the intermediate service responsible for connecting a GitLab instance with various large language models and artificial intelligence providers. Its core architecture processes requests and responses related to productivity tools such as GitLab Duo.
For organizations that require strict adherence to data privacy mandates regarding model training and telemetry, GitLab provides an option to deploy their own gateway locally or within private infrastructure. However, because this component handles automated processing logic and sensitive credentials — including JSON Web Token (JWT) signing keys and external model integrations — it represents a high-value attack surface.
Vulnerability Data
-
CVE-2026-90970 (NVD Verified):
- CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Score: 9.9 (CRITICAL)
- CWE Classification: CWE-1336 (Improper Control of Generation of Code / Template Injection)
- CISA KEV: Not reported in the catalog as of publication date.
- CVSS v3.1 Vector:
-
CVE-2026-1868 (Historical NVD Verified Precedent):
- CVSS v3.1 Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H - Score: 9.9 (CRITICAL)
- CWE Classification: CWE-1336
- CVSS v3.1 Vector:
How Does It Work? (Technical Analysis)
The technical flaw stems from insecure handling of prompt templates within custom workflows inside the Duo Agent Platform, which allows users to automate multi-step tasks using AI.
- Initial Exploit Entry Flow: An attacker with authenticated access to the agent platform generates or modifies a Duo Agent Platform Flow definition using a maliciously structured template configuration.
- Sandbox Escape and Code Execution: During the expansion of user-supplied data within the template engine, internal validation fails to properly restrict the execution context. This triggers a breakout from the secure template sandbox, enabling template injection and subsequent arbitrary command execution on the gateway’s operating system.
- Credential Exposure: Because a self-hosted gateway retains authentication tokens and external model provider credentials, successful exploitation jeopardizes the confidentiality and integrity of the entire connected infrastructure.
Affected Systems / Environments
The impact is strictly limited to organizations operating their own self-hosted AI Gateway infrastructure. Customers managed directly by GitLab in cloud or dedicated environments (GitLab.com and GitLab Dedicated) received centralized mitigations prior to public disclosure.
Affected Versions and Patches Matrix
| CVE | Affected AI Gateway Versions | Initial Patched Version |
|---|---|---|
| CVE-2026-90970 | 18.1.6 up to 19.2.4 (excl.) 19.3 up to 19.3.2 (excl.) 19.4 up to 19.4.1 (excl.) |
19.2.4, 19.3.2, 19.4.1 |
| CVE-2026-1868 | 18.1.6, 18.2.6, 18.3.1 through 18.6.1, 18.7.0, 18.8.0 | 18.6.2, 18.7.1, 18.8.1 |
Mitigation and Detection
Remediation
Administrators running self-hosted instances must immediately upgrade the AI Gateway component to the patched versions corresponding to their active support line (19.2.4, 19.3.2, or 19.4.1).
- Docker Deployments: Stop and remove the running container, pull the updated image tag, and restart the service (e.g.,
self-hosted-v19.4.1-ee). - Helm Chart Deployments: Update the image tag parameter in the Helm chart configuration.
Operational Warning: As no workarounds are currently available for instances unable to update immediately, applying the official software updates remains the sole effective mitigation path.
Detection
Incident response teams and SOC analysts should focus monitoring efforts on:
- Inspecting AI Gateway access logs for unusual request patterns or suspicious bulk modifications to Duo Agent Platform flow definitions.
- Monitoring for unexpected child processes spawned by the gateway container or service (such as unauthorized shell interpreters like
sh,bash,python, or anomalous network connections).
Wrapping Up
The identification and patching of CVE-2026-90970 highlight inherent security risks associated with integrating dynamic template engines into modern artificial intelligence platforms. The ability to escape a sandbox via manipulated flow configurations demonstrates that AI-driven automation interfaces require rigorous input sanitization controls. Organizations maintaining self-hosted deployments of GitLab AI Gateway must prioritize these security updates to mitigate the risk of remote command execution.
References
- GitLab. (2026). GitLab AI Gateway patch release: 19.4.1, 19.3.2, 19.2.4. https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/
- CVEProject. (2026). CVE-2026-90970 JSON Record. https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/90xxx/CVE-2026-90970.json
- GitLab. (2026). GitLab Duo Self-Hosted Documentation. https://docs.gitlab.com/administration/gitlab_duo_self_hosted/
- GitLab. (2026). Upgrade the AI Gateway Docker Image. https://docs.gitlab.com/install/install_ai_gateway/#upgrade-the-ai-gateway-docker-image
- GitLab. (2026). Maintenance Policy and Supported Versions. https://docs.gitlab.com/policy/maintenance/#maintained-versions
- GitLab. (2026). Patch Release: GitLab AI Gateway 18.8.1 (CVE-2026-1868). https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-18-8-1-released/
- National Vulnerability Database. (2026). NVD - CVE-2026-90970. https://gitlab.com/gitlab-org/gitlab/-/work_items/628842
- National Vulnerability Database. (2026). NVD - CVE-2026-1868. https://about.gitlab.com/releases/2026/02/06/patch-release-gitlab-ai-gateway-18-8-1-released/