← All security news

GitLab Patches Critical AI Gateway RCE Flaw

A GitLab AI Gateway box with a crafted flow configuration breaking out of a sandboxed prompt template boundary into a command execution shell, representing CVE-2026-90970

GitLab has patched a critical flaw, tracked as CVE-2026-90970 and rated 9.9 out of 10 on the CVSS scale, in the AI Gateway component that powers its Duo Agent Platform features on self-hosted installations. A logged-in user who already had access to Duo Agent Platform could craft a custom "flow" configuration that escaped the sandbox meant to contain AI prompt templates, letting them run arbitrary commands on the underlying server. GitLab.com's hosted SaaS service was never exposed and needed no customer action; the risk sits entirely with organisations running their own GitLab AI Gateway.

The flaw affects self-hosted AI Gateway 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Fixes landed in 19.2.4, 19.3.2, and 19.4.1. GitLab credits a researcher using the handle "invisiblemeerkat," reported through HackerOne, and says it reached out directly to known affected self-hosted customers ahead of the public advisory. As of 2 October, CISA listed exploitation status as "none" — no confirmed attacks in the wild, but the bug requires only an authenticated account with Duo Agent Platform access, not an administrator, which is a comparatively low bar inside a company that has turned the feature on for its developers. It's also the second critical sandbox-escape in GitLab's AI template engine this year, after a near-identical CVSS 9.9 flaw (CVE-2026-1868) in February — the same category of bug showing up twice in eight months.

What this means for your business

If your business runs GitLab on its own servers — rather than gitlab.com — and has Duo Agent Platform's AI coding-agent features turned on, check your AI Gateway version this week and upgrade to 19.2.4, 19.3.2, or 19.4.1 (or whichever later release you're tracking). The Gateway is typically deployed separately via Docker or Helm alongside core GitLab, so it's worth confirming with whoever manages your GitLab infrastructure that it was actually included in your last update, not assumed to be covered by a core GitLab patch.

The wider pattern matters even if you're not a GitLab customer: as more development tools add AI agents that can read code, call APIs, or execute "flows" on your behalf, the sandbox around that agent is now part of your attack surface, not just an implementation detail. Any team adopting an AI coding assistant, agent platform, or automation tool this year should ask the vendor a direct question — what happens if a logged-in user tries to break out of the sandbox — rather than assuming "AI feature" and "safe by default" mean the same thing.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Hacker News