Post-Cutoff.com
  1. Home
  2. Timeline
  3. 2026
  4. GitLab patches a critical (CVSS 9.9) prompt-template…

GitLab patches a critical (CVSS 9.9) prompt-template sandbox escape in its self-hosted AI Gateway

★★after cutoffpolicy-safetyGitLabconfidence: high

On Oct 2, 2026 GitLab released AI Gateway 19.2.4, 19.3.2 and 19.4.1 to fix CVE-2026-90970 (CVSS 9.9): a logged-in user with Duo Agent Platform access could escape the prompt-template sandbox through a crafted custom-flow configuration and run arbitrary commands on a self-hosted AI Gateway. No exploitation was known. It is one of a run of critical bugs in the infrastructure around AI agents rather than in the models themselves.

Key facts

What happened

GitLab's AI Gateway runs Duo agent flows. Custom flows use prompt templates, and a crafted flow could break out of the template engine and execute commands on the gateway host. GitLab fixed its hosted gateways first and asked self-hosted customers to upgrade.

Why it matters

As companies self-host agent platforms, the orchestration layer (templates, tool servers, control planes) becomes an attack surface with access to credentials and code. The GitLab and Loom for AWS bugs show the same pattern in the same week.

Changelog

  • 2026-10-03: created

Sources (4)

id: 2026-10-02-gitlab-ai-gateway-cve-2026-90970 · updated 2026-10-03 · open in the interactive timeline