GitLab Warns of Critical AI Gateway Vulnerability Allowing Arbitrary Command Execution
GitLab has released security updates for its self-hosted AI Gateway after discovering a critical vulnerability that could allow authenticated attackers to execute arbitrary commands.
GitLab AI Gateway vulnerability requires immediate patching
GitLab is warning customers to immediately patch a critical vulnerability in its AI Gateway that could allow attackers to execute arbitrary commands on vulnerable instances.
GitLab AI Gateway provides access to AI-native GitLab Duo functionality. GitLab operates cloud-based AI Gateway instances used by GitLab.com, GitLab Self-Managed, and GitLab Dedicated. Customers can also deploy self-hosted instances through GitLab Duo Self-Hosted on GitLab Self-Managed.
CVE-2026-90970 could enable arbitrary command execution
Tracked as CVE-2026-90970, the flaw involves the improper neutralization of special elements used in a template engine. An attacker with basic privileges and access to the Duo Agent Platform could exploit the vulnerability to execute arbitrary commands on an unpatched AI Gateway instance.
CWE-1336 classifies the issue as improper neutralization of special elements used in a template engine.
“GitLab has fixed an issue in GitLab AI Gateway that, under certain conditions, could allow an authenticated user with access to the Duo Agent Platform to escape from the prompt template sandbox via a specially crafted flow configuration and execute arbitrary commands on the AI Gateway,” the company explained in a Friday advisory.
GitLab releases patched AI Gateway versions
GitLab has released versions 19.2.4, 19.3.2, and 19.4.1 to address CVE-2026-90970 in self-hosted AI Gateway deployments.
Customers using GitLab’s hosted AI Gateway are already protected and do not need to take action. However, GitLab Self-Managed customers running GitLab Self-Hosted AI Gateway should update immediately.
“These versions contain important security fixes for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers who have GitLab Self-Hosted AI Gateway installed update to one of these versions immediately,” GitLab said. “We conducted targeted outreach to self-hosted AI Gateway customers following this guidance prior to this release post.”
GitLab said it contacted organizations hosting their own AI Gateway instances before publicly disclosing the vulnerability. The company also urged customers to upgrade vulnerable AI Gateway Docker images as soon as possible.
Previous GitLab vulnerability was added to CISA’s exploited vulnerabilities list
Last month, GitLab also patched a maximum-severity path traversal vulnerability, tracked as CVE-2026-85706, in GitLab Community Edition and Enterprise Edition.
The vulnerability allowed unauthenticated attackers to read sensitive information, including credentials, from vulnerable servers.
The following day, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85706 to its Known Exploited Vulnerabilities Catalog. Under Binding Operational Directive 26-04, federal agencies were given three days to secure affected systems.
Since November 2021, CISA has listed five GitLab vulnerabilities as being exploited in the wild, including by ransomware groups.
GitLab says its DevSecOps platform has more than 30 million registered users and is used by more than 50% of Fortune 100 companies, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS.
Join Mikko Hypponen and security leaders from the NFL, Chanel, and Atlassian for a two-hour digital summit about what will change with AI-speed attacks, what defenders should stop doing, and how to verify, decide, fix, and revalidate at machine speed.
Source: www.bleepingcomputer.com



