GitLab has issued an urgent advisory for a critical flaw in its AI Gateway component. Tracked as CVE-2026-90970, it lets an authenticated attacker run code on self-hosted servers. The CVSS v4.0 base score is 9.9, the maximum, and it affects organizations that self-host the gateway to support GitLab Duo AI features.
GitLab has already patched its managed cloud environments. Administrators of self-hosted AI Gateways have to apply the new patches themselves. The flaw bypasses the sandbox meant to contain AI prompt executions, which can give an attacker deep access to the infrastructure that processes sensitive software development lifecycle (SDLC) data.
How the GitLab AI Gateway fits into a DevSecOps pipeline
The AI Gateway is a central proxy that connects a GitLab instance to external Large Language Model (LLM) providers. Enterprises with strict data sovereignty and compliance requirements often self-host it so that proprietary source code, internal telemetry, and AI prompts stay inside the corporate network perimeter.
That setup concentrates risk in one place. The self-hosted gateway stores sensitive credentials, including JSON Web Token (JWT) signing keys, and keeps persistent connections to both the GitLab control plane and the organization’s private AI model backends. A compromised gateway gives an attacker far more than a manipulated code suggestion. They get a foothold in the wider infrastructure, from which they can intercept source code, hijack authenticated sessions with stolen JWTs, or pivot to internal LLM endpoints.
The sandbox escape mechanism
The bug sits in how custom flow prompt templates are handled in the GitLab Duo Agent Platform. The platform lets developers build multi-step, AI-automated workflows for tasks across the software lifecycle. To stop malicious code injection, GitLab runs these prompt templates inside a restricted execution sandbox.
CVE-2026-90970 is a sandbox escape. Under specific conditions, an authenticated user with Duo Agent Platform access can submit a crafted flow configuration. The payload exploits a weakness in the underlying template engine, gets past the sanitization routines, and breaks out of the sandbox. From there the attacker can run arbitrary commands in the context of the AI Gateway service.
The published CVSS vector describes a network-accessible attack with low complexity and low privilege requirements. The attacker needs a valid user account, so this is not an unauthenticated, zero-click exploit. Compromised developer credentials, phishing, and malicious insiders are all realistic ways to get one, and that keeps the risk critical for enterprise environments.
A repeat of February’s template engine flaw (CWE-1336)
In February 2026, GitLab patched CVE-2026-1868, another CVSS 9.9 flaw. Both bugs belong to the same class of template engine weakness (CWE-1336), and both involve crafted flow definitions that lead to code execution or Denial of Service (DoS) on the gateway.
Two template injection flaws in the same component suggest that processing dynamic, user-generated AI workflows is hard to secure. Agentic systems let user-defined logic reach backend execution environments directly, so input validation has to be strict.
Affected and fixed versions
The AI Gateway is installed as its own Docker image or Helm chart, with a version number separate from the main GitLab instance. Check the gateway deployment’s version directly, because the GitLab instance version will not tell you whether you are exposed.
📬 Stay Ahead of Cyber Threats
Get the latest cybersecurity news, critical vulnerabilities, threat intelligence, tutorials, and exclusive giveaways delivered straight to your inbox. No spam. Unsubscribe anytime.
Subscribe to the Newsletter →Affected AI Gateway versions:
- 18.1.6 through 19.2.3
- 19.3.0 through 19.3.1
- 19.4.0
Fixed AI Gateway versions:
- 19.2.4
- 19.3.2
- 19.4.1
GitLab has not released a patch for the 19.1 branch or any earlier line. Gateways on those branches need to move to a supported minor release (19.2, 19.3, or 19.4).
Who is affected
Customers on GitLab.com, GitLab Dedicated, and Self-Managed instances connected to a GitLab-hosted AI Gateway are already protected, since GitLab has deployed the fix to its managed infrastructure. Organizations running their own self-hosted AI Gateway are the ones at risk, and they have to install the update themselves.
Mitigation and hardening for self-hosted deployments
The gateway handles cryptographic material and network traffic, so update it carefully. A rushed rollout can leave a cached vulnerable image in place or disrupt active CI/CD pipelines.
Docker deployments
Stop and remove the vulnerable container, pull the patched image (for example, self-hosted-v19.4.1-ee), and restart the service with the right environment variables. Compare the deployed image digest against GitLab’s official release notes to confirm the correct binary is running.
Kubernetes and Helm deployments
GitLab warns that local registry caching can stop the updated code from being pulled. Update the image.tag in your Helm chart values and set imagePullPolicy to Always. For the strongest guarantee, pin the deployment to the verified image digest instead of a floating tag.
Network hardening
Patching is not the only step. Segment the network so the AI Gateway can talk only to the GitLab instance and approved, allowlisted LLM endpoints. Blocking unnecessary outbound internet traffic from the gateway container makes it harder for an attacker to open a reverse shell or exfiltrate data after a sandbox escape.
Threat hunting and indicators of compromise
CISA currently lists active exploitation of CVE-2026-90970 as “none,” and no public Proof-of-Concept (PoC) exploit code has been seen in the wild. The gap between public disclosure and weaponization by advanced persistent threat (APT) groups keeps getting shorter, though, so hunt now rather than wait.
Security operations centers (SOCs) and DevSecOps teams should check the following:
- AI Gateway logs for unusual flow configuration submissions
- Host-level logs for unexpected child processes spawned by the main gateway service
- Network telemetry for unauthorized outbound connections from the gateway’s IP address
Conclusion
AI agents in the software development lifecycle bring real efficiency gains, and they also add complex, dynamic execution environments to the attack surface. AI infrastructure needs the same patch management and network hardening as any production server. If you run a self-hosted GitLab AI Gateway, update it now.









