GitLab patches critical self-hosted AI Gateway command execution flaw

GitLab has released fixes for CVE-2026-90970, a critical vulnerability in its AI Gateway that could allow an authenticated user with Duo Agent Platform access to execute commands on a self-hosted gateway. GitLab assigned the issue a CVSS score of 9.9 out of 10 and disclosed it on October 2, 2026.
The company fixed the vulnerability in AI Gateway versions 19.2.4, 19.3.2 and 19.4.1. The issue concerns organisations that operate their own gateway rather than using one hosted by GitLab.
Custom flow templates are at the centre of the flaw
GitLab said the weakness lies in the prompt template used by a custom flow. Custom flows are AI-powered workflows created in the Duo Agent Platform to automate multi-step tasks. A logged-in user with platform access could escape the prompt-template sandbox through a specially crafted flow configuration, potentially leading to arbitrary command execution on the gateway.
The advisory does not describe the precise conditions required for exploitation and does not name a role beyond Duo Agent Platform access. It also does not state that the flaw has been exploited. On October 2, CISA's assessment in the CVE record listed exploitation as none; the record separately tracks the existence of a public proof of concept and active exploitation.
Who needs to update
GitLab operates AI Gateways for its customers and said it has already remediated those services. GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted gateway do not require customer action for this issue.
Administrators running a self-hosted gateway should update immediately. The gateway is deployed separately from GitLab, either as its own Docker image or through a Helm chart, and follows its own update procedure. Docker users need to replace the running container with an image carrying the corrected tag, while Helm users need to set the updated image tag in the chart configuration.
- Versions 18.1.6 or later and earlier than 19.2.4 are fixed in 19.2.4.
- Version 19.3 releases earlier than 19.3.2 are fixed in 19.3.2.
- Version 19.4 releases earlier than 19.4.1 are fixed in 19.4.1.
No fixed release is listed below 19.2.4, leaving gateway versions from 18.1.6 through the 19.1 line within the affected range. GitLab's installation guidance says the gateway image should match the GitLab minor version, but the advisory does not say whether a 19.2.4 gateway is compatible with GitLab 19.1 or earlier, or whether fixes for those older lines are planned.
Gateway exposure warrants focused review
A self-hosted AI Gateway retains JSON Web Token signing keys, which GitLab identifies as sensitive credentials. It also connects the GitLab instance with an organisation's AI model providers. Command execution on that component could therefore affect a service positioned between development workflows and AI infrastructure.
GitLab listed no workaround for customers that cannot yet update and provided no method for determining whether a gateway was compromised before patching. The company credited HackerOne researcher invisiblemeerkat with reporting the vulnerability. GitLab fixed another critical AI Gateway issue, CVE-2026-1868, in February; both are classified as CWE-1336 template-engine weaknesses.
For businesses operating their own gateway, the practical priority is to inventory Docker and Helm deployments, confirm the installed gateway version, move to the applicable fixed release and assess the handling of gateway credentials and connected AI services.

