A critical vulnerability in GitLab’s AI Gateway has been addressed, preventing potential command execution by users with access to the Duo Agent Platform. This flaw, identified as CVE-2026-90970, affects organizations using self-hosted gateways and was disclosed on October 2, 2026.
Details of the Vulnerability
The AI Gateway connects GitLab instances to AI models, and the flaw could allow authenticated users to execute commands under certain conditions. GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1 to mitigate this risk. The issue has a CVSS score of 9.9 out of 10, emphasizing its severity.
While GitLab’s hosted services are already secured, organizations managing their own gateways are urged to apply these updates without delay. This recommendation was communicated to customers before the public advisory was issued.
Impact and Resolution
The flaw lies in the prompt template of a custom workflow on the Duo Agent Platform, which could be exploited to bypass the template sandbox. This exploitation might result in arbitrary command execution on the gateway.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has noted that there is currently no evidence of active exploitation. However, GitLab advises immediate updates to safeguard systems, as no workarounds are available for those unable to upgrade.
Updating Affected Systems
To update a Docker deployment of the gateway, administrators should stop the running container, remove it, and then deploy the updated image, such as self-hosted-v19.4.1-ee. For Helm deployments, the new image tag should be set in the chart’s configuration.
GitLab’s maintenance policy specifies that versions 19.2, 19.3, and 19.4 are eligible for security fixes, and these versions have received the necessary updates. Users are encouraged to ensure their systems align with these versions to maintain security integrity.
Conclusion and Future Outlook
This critical vulnerability highlights the need for continuous security vigilance in software environments. GitLab has credited the researcher ‘invisiblemeerkat’ on HackerOne for identifying this issue, underscoring the importance of collaborative security efforts.
Looking ahead, organizations should remain proactive in applying security patches and monitoring advisories to protect against potential threats. GitLab’s swift response to this flaw reflects its commitment to maintaining robust security for its users.
