NEWS

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab fixed a critical CVSS 9.9 flaw in its AI Gateway letting authenticated Duo Agent Platform users execute commands on self-hosted servers.

Dylan H.

News Desk

October 3, 2026
5 min read
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

GitLab Rushes Out a Fix for Another AI Gateway Sandbox Escape

GitLab has patched a critical vulnerability in its AI Gateway, the component that connects self-hosted GitLab instances to the Duo Agent Platform and the AI models behind it. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw lets a logged-in user with Duo Agent Platform access submit a specially crafted "flow" configuration that breaks out of the AI Gateway's prompt-template sandbox and runs arbitrary operating-system commands on the gateway host. GitLab disclosed and patched the issue on October 2, 2026, first reported by The Hacker News.

The bug only matters to a specific slice of GitLab's customer base: organizations that run their own, self-hosted copy of the AI Gateway rather than pointing Duo Agent Platform at GitLab's hosted infrastructure. GitLab says it already patched its own GitLab.com and GitLab-hosted AI Gateways server-side before publishing the advisory, so SaaS customers don't need to do anything. Self-hosted AI Gateway operators do.


What Happened

Duo Agent Platform lets users define custom "flows" — automated, multi-step AI-driven workflows that run inside GitLab. To build the prompts those flows send to an AI model, the AI Gateway renders flow configurations through a template engine, inside what is supposed to be a restricted sandbox that keeps template logic from touching the underlying host.

CVE-2026-90970 is a failure of that sandboxing: an authenticated user with access to Duo Agent Platform can craft a flow configuration that escapes the template sandbox during rendering and reaches command execution in the AI Gateway's own runtime. GitLab's advisory classifies the exploit as requiring network access, low attack complexity, low privileges, and no user interaction — and rates confidentiality, integrity, and availability impact all as high, which is how the flaw lands at 9.9 out of 10.

DetailValue
CVE IDCVE-2026-90970
CVSS Score9.9 (Critical)
Affected ComponentGitLab Self-Hosted AI Gateway / Duo Agent Platform custom flows
Affected Versions18.1.6 up to (not including) 19.2.4; 19.3 before 19.3.2; 19.4 before 19.4.1
Fixed Versions19.2.4, 19.3.2, 19.4.1
Privileges RequiredAuthenticated user with Duo Agent Platform flow access
WorkaroundNone
Exploitation StatusNo public PoC indexed; not in CISA's Known Exploited Vulnerabilities catalog as of publication

Because exploitation requires nothing more than the ability to author or edit a flow — not administrative rights — GitLab instances that let a broad set of developers build custom Duo Agent Platform flows carry a larger practical attack surface than the word "authenticated" alone implies.

Notably, this is not the first time this exact component has broken this way. In February 2026, GitLab patched CVE-2026-1868, also rated CVSS 9.9, in the Duo Workflow Service — a near-identical template-engine weakness that let a crafted flow definition trigger denial of service or code execution on the AI Gateway. CVE-2026-90970 arrives roughly eight months later in the same corner of the product, making this the second critical template-sandbox escape disclosed in GitLab's AI agent infrastructure inside a year.


Who Needs to Act

GitLab was direct about scope: if you rely on GitLab.com, GitLab Dedicated, or a GitLab-hosted AI Gateway, no action is required — the backend fix already shipped. The advisory is aimed squarely at teams running their own AI Gateway deployment on-premises or in their own cloud environment.

For those teams:

  • Upgrade immediately to AI Gateway 19.2.4, 19.3.2, or 19.4.1, matching whichever release branch is currently deployed. There is no configuration-based workaround — patching is the only fix.
  • Audit existing flow configurations created by any user with Duo Agent Platform access, looking for unusual template syntax or encoded content that doesn't match legitimate flow authoring.
  • Review who can author flows. Until patched (and as a general hardening step afterward), restrict custom-flow creation to a small, trusted group rather than leaving it open to all developers.
  • Check AI Gateway host logs for unexpected child processes or outbound connections originating from the gateway service, since post-exploitation impact depends heavily on what the gateway container can reach.

There is no evidence of in-the-wild exploitation as of this writing, and no public proof-of-concept exploit has surfaced — but detailed technical write-ups of the bug are already circulating, which historically shortens the runway before working exploits appear. GitLab customers running self-hosted AI Gateway infrastructure should treat this as an urgent, not routine, patch.

CosmicBytez Labs has published a full technical breakdown of the vulnerability, including the attack chain and detection guidance, in our security advisory for CVE-2026-90970.


Sources