GitLab patches a critical (CVSS 9.9) prompt-template sandbox escape in its self-hosted AI Gateway
On Oct 2, 2026 GitLab released AI Gateway 19.2.4, 19.3.2 and 19.4.1 to fix CVE-2026-90970 (CVSS 9.9): a logged-in user with Duo Agent Platform access could escape the prompt-template sandbox through a crafted custom-flow configuration and run arbitrary commands on a self-hosted AI Gateway. No exploitation was known. It is one of a run of critical bugs in the infrastructure around AI agents rather than in the models themselves.
Key facts
- CVE-2026-90970, CVSS 9.9, template-engine weakness (CWE-1336); reported via HackerOne by 'invisiblemeerkat'
- Affected: AI Gateway 18.1.6 up to 19.2.4, 19.3 before 19.3.2, 19.4 before 19.4.1; fixed in 19.2.4, 19.3.2, 19.4.1; no workaround
- Requires an authenticated account with Duo Agent Platform access; GitLab.com, Dedicated and GitLab-hosted gateways were already patched
- CISA's assessment on the CVE record (Oct 2) lists exploitation as 'none'
- Same week: Loom for AWS, an AWS agent control-plane project, disclosed CVE-2026-103956 (CVSS 10), a missing-authentication flaw giving unauthenticated super-admin control in deployments without an identity provider (fixed in 1.6.1, released Aug 4)
What happened
GitLab's AI Gateway runs Duo agent flows. Custom flows use prompt templates, and a crafted flow could break out of the template engine and execute commands on the gateway host. GitLab fixed its hosted gateways first and asked self-hosted customers to upgrade.
Why it matters
As companies self-host agent platforms, the orchestration layer (templates, tool servers, control planes) becomes an attack surface with access to credentials and code. The GitLab and Loom for AWS bugs show the same pattern in the same week.
Changelog
- 2026-10-03: created
Sources (4)
- officialGitLab: AI Gateway 19.4.1 patch release
- pressThe Hacker News: GitLab patches critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers
- pressSecurity Affairs: CVE-2026-90970 critical GitLab AI Gateway flaw fixed
- pressTheHackerWire: CVE-2026-103956, Loom for AWS unauthenticated super-admin takeover
id: 2026-10-02-gitlab-ai-gateway-cve-2026-90970 · updated 2026-10-03 · open in the interactive timeline