In brief

GitLab released fixes on October 2 for CVE-2026-90970, a critical flaw in its AI Gateway, the service that connects GitLab’s AI features to models. A logged-in user with access to the Duo Agent Platform could send a crafted flow configuration and run any command on the gateway.

New to this? Read it in simple words
  • GitLab fixed a serious hole in the server that runs its AI features.
  • A logged-in user could use it to run any command on that server.
  • Only companies that run the AI Gateway themselves need to update.
  • No attacks using the hole have been reported so far.
Words to know
AI Gateway
A server that passes requests from an app’s AI features to the AI models.
Sandbox
A closed space meant to stop code from reaching the rest of a system.
CVSS
A 0 to 10 scale for how serious a security flaw is.

The flaw

GitLab says an authenticated user with Duo Agent Platform access could “escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.”

The flaw is rated 9.9 out of 10 on the CVSS scale. Only a low-privilege login is needed, and no other user has to click anything.

The Hacker News classes it as a template-engine weakness in custom flows. A researcher known as invisiblemeerkat reported it through HackerOne.

Sources123

PATCH CHECK 01
From a crafted flow to commands on the server.

From GitLab’s patch notice of October 2, checked against The Hacker News and Security Affairs.

Who must act

Affected are self-hosted AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. The fixes are versions 19.2.4, 19.3.2 and 19.4.1.

“A fix has already been deployed for GitLab-hosted AI Gateways,” GitLab says. Customers on GitLab.com, GitLab Dedicated, or a GitLab-hosted gateway need do nothing, the company says.

GitLab lists no workaround other than updating.

Sources134

Is it being used?

The Hacker News, Security Affairs and SecurityOnline all report no known attacks so far. GitLab’s notice does not discuss attacks.

It is the second 9.9-rated flaw in the same gateway this year. CVE-2026-1868, fixed in February, also abused templates in Duo agent flows.

AI agents run with access to code and servers, so a weakness in the layer that feeds them prompts can reach far.

Sources234

Sources

Every fact in this story comes from the sources below. Open them to check our work.

  1. 1
  2. 2
  3. 3
    Research · October 2, 2026CVE-2026-90970: Critical GitLab AI Gateway Flaw Fixed Security Affairs
  4. 4
How we checked this story

We read GitLab’s patch notice and compared The Hacker News, Security Affairs and SecurityOnline. The outlets list the affected versions slightly differently, so we use GitLab’s own wording. That no attacks are known comes from the outlets and CISA’s assessment as The Hacker News reports it, not from GitLab.