GitLab released fixes on October 2 for CVE-2026-90970, a critical flaw in its AI Gateway, the service that connects GitLab’s AI features to models. A logged-in user with access to the Duo Agent Platform could send a crafted flow configuration and run any command on the gateway.
New to this? Read it in simple words
- GitLab fixed a serious hole in the server that runs its AI features.
- A logged-in user could use it to run any command on that server.
- Only companies that run the AI Gateway themselves need to update.
- No attacks using the hole have been reported so far.
- AI Gateway
- A server that passes requests from an app’s AI features to the AI models.
- Sandbox
- A closed space meant to stop code from reaching the rest of a system.
- CVSS
- A 0 to 10 scale for how serious a security flaw is.
The flaw
GitLab says an authenticated user with Duo Agent Platform access could “escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.”
The flaw is rated 9.9 out of 10 on the CVSS scale. Only a low-privilege login is needed, and no other user has to click anything.
The Hacker News classes it as a template-engine weakness in custom flows. A researcher known as invisiblemeerkat reported it through HackerOne.
From GitLab’s patch notice of October 2, checked against The Hacker News and Security Affairs.
Who must act
Affected are self-hosted AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. The fixes are versions 19.2.4, 19.3.2 and 19.4.1.
“A fix has already been deployed for GitLab-hosted AI Gateways,” GitLab says. Customers on GitLab.com, GitLab Dedicated, or a GitLab-hosted gateway need do nothing, the company says.
GitLab lists no workaround other than updating.
Is it being used?
The Hacker News, Security Affairs and SecurityOnline all report no known attacks so far. GitLab’s notice does not discuss attacks.
It is the second 9.9-rated flaw in the same gateway this year. CVE-2026-1868, fixed in February, also abused templates in Duo agent flows.
AI agents run with access to code and servers, so a weakness in the layer that feeds them prompts can reach far.
Sources
Every fact in this story comes from the sources below. Open them to check our work.
- 1Primary source · October 2, 2026GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1 GitLab
- 2Research · October 2, 2026GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers The Hacker News
- 3
- 4Research · October 2, 2026GitLab Patches Critical AI Gateway Flaw That Lets Duo Users Run Commands SecurityOnline
We read GitLab’s patch notice and compared The Hacker News, Security Affairs and SecurityOnline. The outlets list the affected versions slightly differently, so we use GitLab’s own wording. That no attacks are known comes from the outlets and CISA’s assessment as The Hacker News reports it, not from GitLab.