GitLab patches a near-perfect-score AI Gateway bug that lets logged-in users run commands on the server

CVE-2026-90970 scores 9.9 out of 10 and lets any authenticated user with Duo Agent Platform access escape a prompt template and execute code. Only self-hosted gateways need the fix.

ThreatVectr Newsdesk· Editor: Lee Brown· 3 min read
Full-frame edge-to-edge photoreal editorial shot of a dimly lit server rack in a corporate data room, a single amber warning LED glowing on a 1U appliance label
Share

Key points

  • GitLab patched a critical flaw in its self-hosted AI Gateway, tracked as CVE-2026-90970, that lets a logged-in user with Duo Agent Platform access escape a prompt template and run commands on the gateway server.
  • Fixed versions are 19.2.4, 19.3.2 and 19.4.1, released this week.
  • GitLab.com, GitLab Dedicated and self-managed customers using the GitLab-hosted gateway are already protected and don't need to act.
  • GitLab says it contacted affected self-hosted customers directly before publishing the advisory.
  • The AI Gateway is a Premium and Ultimate tier component that routes GitLab Duo requests to customer-chosen large language models.

GitLab has shipped an emergency fix for a critical hole in the software that connects its developer platform to AI models. The gateway passes requests from GitLab's Duo assistant to whichever large language model a customer has chosen to run, and it scores a 9.9 out of 10 on the CVSS severity scale.

CVE-2026-90970 is an improper neutralisation issue in a custom flow prompt template. In plain terms: an attacker can smuggle instructions past the guardrails the gateway places around user input. A logged-in user with Duo Agent Platform access can break out of that template and execute commands on the gateway host itself.

Patched versions are 19.2.4, 19.3.2 and 19.4.1. GitLab is telling every self-hosted customer to upgrade immediately. We've now covered five GitLab security stories since 25 July, including the 17 September patch call for two critical server flaws in its enterprise product.

Who actually needs to patch?

Only organisations running their own copy of the AI Gateway. GitLab has already fixed its hosted service, so customers on GitLab.com and GitLab Dedicated, along with self-managed deployments that rely on the GitLab-hosted gateway, don't need to do anything.

Self-hosting the gateway is a choice some larger customers make to keep prompts and model responses inside their own network. It's tied to Premium and Ultimate tiers and used alongside GitLab Duo Self-Hosted or the Duo Agent Platform Self-Hosted add-on. That's a smaller customer slice, but a sensitive one: these are typically regulated firms or companies that have deliberately pulled their AI pipeline off the public internet.

GitLab says it reached out directly to affected customers before publishing the advisory, which is the usual sign a vendor expects exploitation to follow public disclosure quickly.

What could an attacker actually do?

Run code on the AI Gateway host. That's the worst case, and it's why the issue was rated critical.

An account with Duo Agent Platform access is required, so this isn't something a random stranger can trigger. That lowers the drive-by risk and raises the insider and stolen-credential risk. Phish a developer at a company running the self-hosted gateway and that developer's session becomes the launch pad.

A compromised AI Gateway is a damaging position for an attacker. The gateway sees prompts, source-code snippets sent for review, and model responses. It also holds credentials for the backend model, whether that's an internal deployment or a paid API. Our September report on the Bifrost AI Gateway shell bug showed how quickly a misconfigured gateway turns into a server-level foothold.

What should admins do today?

Upgrade the self-hosted AI Gateway to 19.2.4, 19.3.2 or 19.4.1, matching whichever release train you're on.

Component Status Patched versions
Self-hosted AI Gateway Vulnerable, action required 19.2.4, 19.3.2, 19.4.1
GitLab-hosted AI Gateway Already fixed by GitLab n/a
GitLab.com / Dedicated / Self-Managed on hosted gateway Not affected n/a

GitLab's decision to call customers before posting the advisory is the detail worth noticing. Prompt-injection bugs in AI middleware have mostly been treated as content problems. This one is a remote command execution dressed in prompt-template clothing, and any vendor shipping an AI gateway on-prem should expect their own version before long.

© 2026 Threat Vectr