
GitLab has released fixes for a critical vulnerability, CVE-2026-90970 (CVSS 9.9), in its AI Gateway, the service that connects a GitLab instance to the AI models behind its Duo features. Under certain conditions, an authenticated user with Duo Agent Platform access can escape the prompt-template sandbox using a specially crafted flow configuration and execute arbitrary commands on the gateway itself. That is a template-sandbox escape rather than a bug reachable by anonymous visitors, but any account with agent access becomes a path to code execution on the server.
Only organizations that run their own gateway through GitLab Duo Self-Hosted need to act. GitLab says the gateway it operates for GitLab.com, GitLab Dedicated and self-managed customers using the GitLab-hosted gateway is already patched. The advisory does not say the flaw has been exploited, and CISA’s assessment added to the CVE record on October 2 lists exploitation as “none”. GitLab contacted self-hosted customers before publishing the advisory. The disclosure follows a separate GitLab CE/EE flaw (CVE-2026-85706) that CISA added to its Known Exploited Vulnerabilities catalog last month, so GitLab servers remain an active target.
How to check if you’re affected
Affected products are self-hosted GitLab AI Gateway installations (the Docker image or Helm chart deployed for GitLab Duo Self-Hosted). Affected versions run from 18.1.6 through the 19.1 line, and the 19.2, 19.3 and 19.4 lines before the fixed releases below.
- Check the gateway version: this is the AI Gateway image tag, not your GitLab version. Look at the running container or Helm values for a tag such as
self-hosted-v19.4.1-ee. - Update: move to AI Gateway 19.2.4, 19.3.2 or 19.4.1. For Docker, stop and remove the running container, then pull and run the new image tag; for Helm, set the new tag in the chart’s image setting.
- Older lines: GitLab lists no fixed release below 19.2.4, and its advisory does not say whether a newer gateway works with GitLab 19.1 or earlier. Check GitLab’s install guide for the matching image or plan a GitLab upgrade.
- Until you can patch: limit who holds Duo Agent Platform access and restrict network reach from the gateway to internal systems.
