Overview
GitLab has patched a critical vulnerability in the AI Gateway component that powers Duo Agent Platform custom flows. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw lets an authenticated user with Duo Agent Platform access supply a crafted flow configuration that escapes the prompt template sandbox and executes arbitrary operating system commands on the AI Gateway host.
The issue only affects organizations that self-host the AI Gateway. GitLab.com and GitLab-hosted AI Gateway instances were already patched server-side before the advisory was published, and GitLab reportedly reached out to affected self-hosted customers directly given the sensitivity of the component.
Technical Details
| Field | Value |
|---|---|
| CVE ID | CVE-2026-90970 |
| Severity | Critical (CVSS 9.9) |
| Attack Vector | Network |
| Authentication | Required — Duo Agent Platform access |
| Privileges Required | Low (any user with flow access) |
| User Interaction | None |
| Impact | Arbitrary command execution on the AI Gateway host |
How It Works
The AI Gateway renders prompt templates for Duo Agent Platform's custom flows inside a restricted sandbox meant to prevent template logic from reaching the underlying host. CVE-2026-90970 is an improper-sanitization issue in that sandbox: a specially crafted flow configuration can break out of the intended isolation and reach command execution in the AI Gateway's runtime.
Because exploitation only requires a flow-authoring user — not an administrator — any organization that lets a broad set of users author or edit Duo Agent Platform flows has a meaningfully larger exposure window than the "authenticated" label might suggest.
Impact Assessment
Who Is At Risk
- Organizations running a self-hosted AI Gateway on any of the affected branches: 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1
- Self-managed GitLab instances with Duo Agent Platform enabled and custom flows available to users
- Multi-tenant or shared GitLab deployments where flow-authoring permissions are broadly granted
GitLab SaaS customers and anyone relying solely on GitLab-hosted AI Gateway infrastructure are not required to take action — the fix was already deployed on that side.
Potential Attack Chains
- Flow Authoring — An authenticated user with Duo Agent Platform access crafts a malicious flow configuration
- Sandbox Escape — The crafted template breaks out of the prompt-template sandbox during rendering
- Command Execution — Arbitrary commands run in the context of the AI Gateway service
- Pivot/Exfiltration — Depending on host configuration, the AI Gateway process may reach credentials, internal network segments, or other integrated services
Mitigation
Immediate Actions
- Upgrade self-hosted AI Gateway to one of the fixed releases: 19.2.4, 19.3.2, or 19.4.1 (apply the fix matching your current release branch)
- There is no workaround — patching is the only remediation
- Until patched, consider restricting Duo Agent Platform custom-flow authoring to a minimal, trusted set of users
- Confirm whether your instance is self-hosted vs. relying on GitLab-hosted AI Gateway infrastructure, since only self-hosted deployments are exposed
Detection Opportunities
- Review AI Gateway host logs for unexpected child processes spawned from the gateway service
- Audit recently created or modified Duo Agent Platform flow configurations for unusual template syntax or encoded payloads
- Monitor outbound connections initiated by the AI Gateway host for anomalous destinations
Background
This is notable as one of the first critical remote-code-execution vulnerabilities disclosed in an AI-specific infrastructure component of a major DevOps platform, and GitLab's Duo Workflow Service has now had two CVSS 9.9 template-engine escapes disclosed within eight months. As AI agent platforms take on more autonomous actions inside developer tooling, sandbox-escape classes like this one are likely to recur — defenders running self-hosted AI agent infrastructure should treat prompt-template and flow-execution sandboxes as a first-class attack surface, not an afterthought.
No public proof-of-concept has been indexed and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog, but given the severity and detailed technical write-ups already circulating, defenders should patch promptly rather than wait for confirmed in-the-wild exploitation.