Back
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
SiTech AI Team2 min read

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab has patched a critical AI Gateway vulnerability, tracked as CVE-2026-90970 and rated 9.9 on the CVSS scale. Only organizations that self-host their gateway need to act; fixes ship in versions 19.2.4, 19.3.2 and 19.4.1.

GitLab has patched a critical vulnerability in its AI Gateway, the service that connects a GitLab instance to AI models. The flaw is tracked as CVE-2026-90970 and rated 9.9 on the CVSS scale; GitLab disclosed it on October 2.

How the flaw works

According to the advisory, the weakness sits in the prompt template of a custom flow, an AI-powered workflow that users build on the Duo Agent Platform to automate multi-step tasks. A logged-in user with Duo Agent Platform access could escape the prompt template sandbox through a specially crafted flow configuration, which could lead to arbitrary command execution on the gateway. The advisory does not describe the conditions the attack requires or name any user role beyond Duo Agent Platform access.

Who needs to update

The flaw is fixed in AI Gateway versions 19.2.4, 19.3.2 and 19.4.1. The affected range covers gateway releases from 18.1.6 up to 19.2.4, plus 19.3 before 19.3.2 and 19.4 before 19.4.1. No fixed version exists below 19.2.4, so every release from 18.1.6 through the 19.1 line stays affected.

Only organizations that self-host their gateway need to act. GitLab.com, GitLab Dedicated and self-managed instances that use a GitLab-hosted gateway are unaffected, the company said, because GitLab already updated its own gateways. For Docker deployments, administrators stop and remove the running container and pull the new image tag, for example self-hosted-v19.4.1-ee; Helm deployments set the new tag in the chart's image setting. The advisory lists no workaround and no way to check whether a gateway was attacked before it was updated.

Why it matters

A self-hosted gateway holds the signing keys for JSON Web Tokens (JWTs) that GitLab's install guide says must be treated as sensitive credentials. It also connects to the GitLab instance and to the organization's AI model providers.

The advisory does not say whether the flaw has been exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an assessment to the CVE record on October 2 listing exploitation as "none". GitLab credited the HackerOne user invisiblemeerkat with reporting the issue. In February, GitLab fixed another AI Gateway flaw, CVE-2026-1868, also rated 9.9; both are template engine weaknesses of the same class, CWE-1336.

SSiTech

SiTech — AI-powered web development

We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.