GitLab has patched a critical vulnerability in its AI Gateway, the service that connects GitLab instances to AI models. Tracked as CVE-2026-90970 and rated 9.9 out of 10, the flaw could let a logged-in user with Duo Agent Platform access escape the prompt template sandbox of a custom flow via a specially crafted flow configuration, leading to arbitrary command execution on the gateway. GitLab disclosed the issue on October 2 and credited HackerOne user invisiblemeerkat with reporting it.

Only organizations that host their own AI Gateway need to act. GitLab runs AI Gateways for its customers and has already fixed them, so customers on GitLab.com, GitLab Dedicated, and self-managed instances using a GitLab-hosted gateway are not affected. Self-managed customers who run their own gateway to keep AI request and response data inside their own environment are urged to update immediately. Fixed versions are 19.2.4, 19.3.2, and 19.4.1; no fixed version is listed below 19.2.4, leaving every gateway release from 18.1.6 through the 19.1 line in the affected range.

GitLab's advisory does not say whether the flaw has been exploited in attacks, and CISA's assessment lists exploitation as "none." No workaround is available for gateways that cannot be updated yet, and the advisory gives no way to check whether a gateway was attacked before updating. The flaw is similar in class to CVE-2026-1868, another 9.9-rated gateway vulnerability GitLab fixed in February; both are template engine weaknesses tracked as CWE-1336, though the new advisory does not mention the earlier flaw.