GitLab Patches Critical AI Gateway Flaw Allowing Arbitrary Command Execution
Brief
GitLab has released critical security updates for its AI Gateway to address CVE-2026-90970, a vulnerability that could allow authenticated users to execute arbitrary commands on vulnerable self-hosted deployments.
The flaw carries a CVSS score of 9. 9 out of 10 and affects GitLab AI Gateway versions beginning with 18.
- 6 across several release branches.
GitLab issued patched AI Gateway releases 19.
- 4, 19.
- 2, and 19.
- 1, urging all customers operating a GitLab Self-Hosted AI Gateway to upgrade immediately.
GitLab Patches Critical AI Gateway Flaw
Tracked as CVE-2026-90970, the issue stems from improper neutralization in the custom-flow prompt template mechanism used by GitLab AI Gateway.
Under certain conditions, an authenticated user who has access to the Duo Agent Platform could submit a specially crafted flow configuration and escape the prompt-template sandbox.
