GitLab patches CVE-2026-90970 in AI Gateway rated CVSS 9.9
GitLab released fixes for CVE-2026-90970 in its AI Gateway: an authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a crafted flow configuration and execute arbitrary commands on the gateway. Affected versions are 18.1.6–19.2.3, 19.3.0–19.3.1 and 19.4.0; fixes shipped in 19.2.4, 19.3.2 and 19.4.1. GitLab-hosted gateways were patched in advance, leaving self-managed customers with self-hosted gateways exposed.
- CVSS 9.9 with a scope change and high impact across confidentiality, integrity and availability
- Affected AI Gateway versions: 18.1.6–19.2.3, 19.3.0–19.3.1 and 19.4.0
- Fixed releases are 19.2.4, 19.3.2 and 19.4.1
- GitLab.com, GitLab Dedicated and GitLab-hosted gateways are already protected
Read next
Security