GitLab warns of critical RCE flaw in AI Gateway service
GitLab disclosed a critical AI Gateway vulnerability, CVE-2026-90970, that lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox and run arbitrary commands. Fixes are available in versions 19.2.4, 19.3.2 and 19.4.1 for Self-Hosted AI Gateway; GitLab-hosted instances are already protected.
- CVE-2026-90970 allows arbitrary command execution on vulnerable instances
- Patches shipped in versions 19.2.4, 19.3.2 and 19.4.1 for Self-Hosted AI Gateway
- GitLab-hosted AI Gateway is already protected, no action needed
- Flaw affects users with Duo Agent Platform access
Read next
Security