GitLab Patches CVSS 9.9 RCE in Its AI Gateway
On October 2, 2026, GitLab disclosed CVE-2026-90970 (CVSS 9.9) in its AI Gateway: an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox and run arbitrary commands. Fixes shipped in versions 19.2.4, 19.3.2 and 19.4.1; GitLab-hosted gateways are patched, self-hosted ones are not.
- CVE-2026-90970: CVSS 9.9 sandbox escape in the AI Gateway prompt templates
- Fixed versions: 19.2.4, 19.3.2 and 19.4.1, released October 2, 2026
- Self-hosted gateways from 18.1.6 are vulnerable; GitLab.com and Dedicated are patched
- Requires a Duo Agent Platform account; no evidence of exploitation in the wild
Read next
Security