GitLab patches CVSS 9.9 CVE-2026-90970 in AI Gateway
On October 2 GitLab disclosed CVE-2026-90970, a CVSS 9.9 sandbox escape in AI Gateway prompt templates that lets an authenticated Duo Agent Platform user run arbitrary commands. Fixed in 19.2.4, 19.3.2 and 19.4.1; only self-hosted gateways are affected.
- CVSS 9.9, CWE-1336 template injection rather than prompt injection
- Affects self-hosted AI Gateway 18.1.6–19.2.3, 19.3.0–19.3.1 and 19.4.0
- Patches released October 2 in 19.2.4, 19.3.2 and 19.4.1
- Same component had CVE-2026-1868 with the same 9.9 score in February 2026
Read next
Security