SECURITYCRITICALCVE-2026-90970

CVE-2026-90970: GitLab AI Gateway Prompt Template Sandbox Escape

A CVSS 9.9 flaw lets an authenticated Duo Agent Platform user escape the AI Gateway's prompt template sandbox and run commands on self-hosted servers.

Dylan H.

Security Team

October 3, 2026
4 min read
CVE-2026-90970: GitLab AI Gateway Prompt Template Sandbox Escape

Critical severity

Rated critical. Prioritise patching — see the remediation guidance below.

Affected Products

  • GitLab Self-Hosted AI Gateway 18.1.6 – 19.2.3
  • GitLab Self-Hosted AI Gateway 19.3.0 – 19.3.1
  • GitLab Self-Hosted AI Gateway 19.4.0
  • GitLab Duo Agent Platform (custom flows)

Overview

GitLab has patched a critical vulnerability in the AI Gateway component that powers Duo Agent Platform custom flows. Tracked as CVE-2026-90970 and rated CVSS 9.9, the flaw lets an authenticated user with Duo Agent Platform access supply a crafted flow configuration that escapes the prompt template sandbox and executes arbitrary operating system commands on the AI Gateway host.

The issue only affects organizations that self-host the AI Gateway. GitLab.com and GitLab-hosted AI Gateway instances were already patched server-side before the advisory was published, and GitLab reportedly reached out to affected self-hosted customers directly given the sensitivity of the component.


Technical Details

FieldValue
CVE IDCVE-2026-90970
SeverityCritical (CVSS 9.9)
Attack VectorNetwork
AuthenticationRequired — Duo Agent Platform access
Privileges RequiredLow (any user with flow access)
User InteractionNone
ImpactArbitrary command execution on the AI Gateway host

How It Works

The AI Gateway renders prompt templates for Duo Agent Platform's custom flows inside a restricted sandbox meant to prevent template logic from reaching the underlying host. CVE-2026-90970 is an improper-sanitization issue in that sandbox: a specially crafted flow configuration can break out of the intended isolation and reach command execution in the AI Gateway's runtime.

Because exploitation only requires a flow-authoring user — not an administrator — any organization that lets a broad set of users author or edit Duo Agent Platform flows has a meaningfully larger exposure window than the "authenticated" label might suggest.


Impact Assessment

Who Is At Risk

  • Organizations running a self-hosted AI Gateway on any of the affected branches: 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1
  • Self-managed GitLab instances with Duo Agent Platform enabled and custom flows available to users
  • Multi-tenant or shared GitLab deployments where flow-authoring permissions are broadly granted

GitLab SaaS customers and anyone relying solely on GitLab-hosted AI Gateway infrastructure are not required to take action — the fix was already deployed on that side.

Potential Attack Chains

  1. Flow Authoring — An authenticated user with Duo Agent Platform access crafts a malicious flow configuration
  2. Sandbox Escape — The crafted template breaks out of the prompt-template sandbox during rendering
  3. Command Execution — Arbitrary commands run in the context of the AI Gateway service
  4. Pivot/Exfiltration — Depending on host configuration, the AI Gateway process may reach credentials, internal network segments, or other integrated services

Mitigation

Immediate Actions

  • Upgrade self-hosted AI Gateway to one of the fixed releases: 19.2.4, 19.3.2, or 19.4.1 (apply the fix matching your current release branch)
  • There is no workaround — patching is the only remediation
  • Until patched, consider restricting Duo Agent Platform custom-flow authoring to a minimal, trusted set of users
  • Confirm whether your instance is self-hosted vs. relying on GitLab-hosted AI Gateway infrastructure, since only self-hosted deployments are exposed

Detection Opportunities

  • Review AI Gateway host logs for unexpected child processes spawned from the gateway service
  • Audit recently created or modified Duo Agent Platform flow configurations for unusual template syntax or encoded payloads
  • Monitor outbound connections initiated by the AI Gateway host for anomalous destinations

Background

This is notable as one of the first critical remote-code-execution vulnerabilities disclosed in an AI-specific infrastructure component of a major DevOps platform, and GitLab's Duo Workflow Service has now had two CVSS 9.9 template-engine escapes disclosed within eight months. As AI agent platforms take on more autonomous actions inside developer tooling, sandbox-escape classes like this one are likely to recur — defenders running self-hosted AI agent infrastructure should treat prompt-template and flow-execution sandboxes as a first-class attack surface, not an afterthought.

No public proof-of-concept has been indexed and the flaw is not currently listed in CISA's Known Exploited Vulnerabilities catalog, but given the severity and detailed technical write-ups already circulating, defenders should patch promptly rather than wait for confirmed in-the-wild exploitation.


References