
A 9.9 in GitLab's AI Gateway — and Upgrading GitLab Won't Fix It
Mahmud Hasan
October 6, 2026
On October 2, GitLab disclosed CVE-2026-90970, a 9.9-rated critical flaw in its self-hosted AI Gateway. Any logged-in user with Duo Agent Platform access could escape the prompt-template sandbox through a crafted flow configuration and run arbitrary commands on the gateway itself.
That sentence is scary enough. But the part that should make busy admins flinch is duller and worse: the AI Gateway is a separately versioned component, so the GitLab upgrade you already ran this month doesn't touch it. If you patched GitLab CE or EE and went back to your sprint, you may have patched everything except the thing with the 9.9.
What broke: a template engine trusted too far
GitLab's Duo Agent Platform lets users define custom "flows" — multi-step, AI-driven workflows that run inside GitLab. To build the prompts those flows send to a model, the AI Gateway renders flow configurations through a template engine, inside what was supposed to be a restricted sandbox: template logic in, no touching the host.
The sandbox didn't hold. An authenticated user could submit a flow configuration crafted to break out during rendering and reach command execution in the gateway's own runtime. GitLab's advisory rates it as network-reachable, low attack complexity, low privileges required, no user interaction — with confidentiality, integrity, and availability impact all marked high. That's the math behind CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H and a 9.9 score.
Here's the detail worth not missing: this is not a prompt-injection story. The injection fires in the template engine before any language model is invoked — server-side template injection, classified under CWE-1336. The AI never saw anything. The boring plumbing around the AI did the damage. If your mental model of "AI security" starts and ends with jailbroken chatbots, this CVE is a correction.
Why the gateway is the worst seat in the house
The AI Gateway isn't a peripheral widget. It sits directly between your GitLab instance and every AI model provider your organization uses — preparing prompts, ferrying code and diffs to models, and carrying the results back. Prompts, source code, and model credentials all pass through it.
It also holds secrets. GitLab's own install guidance treats the gateway's JWT signing keys as sensitive credentials. So a sandbox escape on this box doesn't just land an attacker in some sandbox — it lands them in the one service that can mint trusted tokens and read the code flowing to the model providers. That's the "S:C" (scope changed) in the CVSS vector: the blast radius extends past the gateway itself.
The upgrade that doesn't fix it
This is the part that will bite people. The flaw affects gateway versions 18.1.6 up to (but not including) 19.2.4, all of 19.3 before 19.3.2, and 19.4 before 19.4.1. The fixes ship as 19.2.4, 19.3.2, and 19.4.1 — of the gateway, not of GitLab.
Core GitLab and the AI Gateway are different services with different release trains. Updating your GitLab instance does nothing to the gateway image. If you self-host, you need to check the deployed gateway container image or Helm configuration — the version string your GitLab admin panel shows you is the wrong number to look at.
The good news is narrow but real: GitLab.com, GitLab Dedicated, and self-managed instances that point at a GitLab-hosted gateway are already patched; GitLab says it remediated its own fleet. And before going public, GitLab did targeted outreach to customers known to run a self-hosted gateway. If you run one and never got that email, treat the silence as a signal — check your contact details with GitLab and patch anyway.
This keeps happening to the same component
Once is an incident; twice is a pattern. In February, GitLab patched CVE-2026-1868 — also 9.9, also the AI Gateway, also exploitable through a crafted flow definition, also a template-engine weakness. This month's advisory doesn't reference it, but the two bugs are classified under the same weakness family. And in September, a separate GitLab path-traversal flaw (CVE-2026-85706) made CISA's actively-exploited list.
The honest counter-argument: this one needs an authenticated user, there's no public proof-of-concept, and CISA lists exploitation as "none." All true. But Duo Agent Platform access is exactly the permission that gets handed out to every developer on the team, and the entire threat model here is a stolen developer token or one malicious insider. "Authenticated-only" stops being comforting the moment you count how many of your authenticated users are contractors.
What to do this week
- Find your gateway version, not your GitLab version. Check the deployed gateway container image tag or Helm chart values. If it sits anywhere in the affected ranges, you're exposed regardless of what GitLab's version says.
- Upgrade the gateway to 19.2.4, 19.3.2, or 19.4.1, matching whichever release branch you run. There is no workaround listed in the advisory — the patch is the fix.
- Audit Duo Agent Platform access. Anyone who can create or modify custom flows is inside the attack's privilege boundary. Trim that list, and treat flow configurations with the same suspicion you'd give any code that runs server-side.
- Watch the gateway logs for unusual flow configurations or template-render errors in the meantime. No exploitation has been confirmed, which makes this the rare week where the patching window is still open.
Template engines are one of the oldest attack surfaces in web software, and they keep getting trusted with more power — now they're the front door of AI agent infrastructure. The lesson of CVE-2026-90970 isn't that AI is dangerous. It's that the scaffolding around AI is still plain old software, with plain old bugs, in components nobody remembers to patch.
References
- CyberPress — GitLab Patches Critical AI Gateway Flaw Allowing Arbitrary Command Execution (includes full CVSS vector and affected version ranges)
- Obiguard — GitLab AI Gateway RCE: CVE-2026-90970 Explained (reporting on GitLab's Oct 2 advisory and BleepingComputer coverage)
- ThaiCERT — GitLab Patches Critical AI Gateway Vulnerability (Oct 5, 2026)
- CosmicBytez Labs — GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers (technical detail table)
- ThreatBeat — Cyber Briefing, October 5, 2026 (weekly context, citing The Hacker News)
Comments
More in Technology

Node.js Is Slowing Down on Purpose. The Reason Is a Maintainer Crisis.
One release a year, every release LTS — it sounds like a gift to developers. The numbers behind Node.js's schedule change tell a different story.
Read more
RAM Is Up 500% in a Year. Micron Just Extended the Shortage to 2028.
Memory prices are up fivefold in a year, and Micron's CEO says he cannot see when supply and demand rebalance. What the earnings call actually means for your next PC purchase.
Read more
Qualcomm Just Paid Huawei for Its Ideas. That's Not a Truce — It's a Receipt.
On Monday, Qualcomm and Huawei signed a multi-year patent cross-license covering 5G, AI, compute, and networking — and Qualcomm is buying some of Huawei's U.S. patents outright. Twenty-five years after Huawei paid Qualcomm its first licensing check, the money just flipped.
Read more