- GitLab fixed CVE-2026-90970, a 9.9-rated flaw that let a signed-in Duo user run commands on the AI Gateway through a crafted flow configuration.
- Hosted customers are already protected. Organisations running their own gateway must apply the patch themselves, so self-hosting carries a patching duty.
- Check your gateway version against the advisory's affected ranges, move to a patched release, and review who can edit flow configurations.
Companies that host their own AI tools do so for control. A recent GitLab patch shows the other side of that choice. When you run the AI service yourself, you also own the repair work.
GitLab published fixes for its AI Gateway, the service behind its Duo AI features. The flaw is tracked as CVE-2026-90970. In GitLab's account, a logged-in user with Duo Agent Platform access could, in some circumstances, break out of the box that confines prompt templates. The trigger was a specially crafted flow configuration. The outcome was arbitrary command execution on the AI Gateway.
What actually broke
A prompt template is the text scaffold that tells an AI model what to do. It can include fields filled in at run time. To keep those templates from doing anything dangerous, the gateway runs them inside a sandbox. A sandbox is a fenced area that limits what the code inside can touch.
GitLab classes the weakness as improper neutralization in the custom flow prompt template. In plain terms, input that should have stayed inert got treated as instructions. A user who could write a flow configuration could step outside the fence. From there they could run commands on the gateway itself.
The severity score reflects how little an attacker needs. The vector GitLab published reads network access, low complexity, low privileges and no user interaction. It also marks scope as changed. In CVSS terms, that means the damage can reach past the vulnerable component. Confidentiality, integrity and availability are all rated high.
Who is exposed, and who is not
Scope matters here. GitLab says it has already fixed the AI Gateways it hosts. Customers on GitLab.com, GitLab Dedicated, and Self-Managed instances that use a GitLab-hosted gateway need to do nothing.
The exposure sits with organisations that run their own gateway through GitLab Duo Self-Hosted. The advisory lists three affected ranges. The first runs from 18.1.6 up to, but not including, 19.2.4. The second covers 19.3 releases before 19.3.2. The third covers 19.4 releases before 19.4.1. Each range ends where a patched release begins. GitLab says it contacted self-hosted customers directly before publishing.
The GitLab notice does not report any exploitation of this flaw. It credits a researcher, invisiblemeerkat, with responsible disclosure.
The idea behind the patch
Security programmes are built to guard source code and servers. This flaw argues that AI configuration deserves the same care. A flow configuration looks like settings. In this case it was a path to running commands.
This is the lesson here: in AI systems, text that steers a model can also be executable. Whoever can edit it holds more power than their job title suggests. The access needed was a signed-in account with Duo Agent Platform access. The published vector rates the privileges required as low.
There is also a quiet split in who carries the risk. Hosted customers got the fix without lifting a finger. Self-hosted customers must find the notice, check their version and schedule the upgrade. Self-hosting buys data control and takes on patching duty in exchange.
Context, kept in proportion
BleepingComputer, which covered the release, reports that GitLab has over 30 million registered users. It says more than 50% of Fortune 100 companies use the platform. Those figures describe GitLab's overall reach. They do not say how many organisations run a self-hosted AI Gateway.
BleepingComputer also notes that last month GitLab patched a separate path traversal flaw, CVE-2026-85706, in its Community and Enterprise editions. CISA added that flaw to its list of actively exploited vulnerabilities. The two flaws affect different components and weakness types. The sources draw no link between them. CISA has tagged five GitLab vulnerabilities as abused in the wild since November 2021, according to the outlet.
Questions to put to your team
First, do we run a self-hosted AI Gateway, and which version is it on? Compare it against the affected ranges above. GitLab strongly recommends upgrading to a patched release.
Second, who holds Duo Agent Platform access, and who can write or change flow configurations? Trim that list to the people who need it.
Third, what can the gateway host reach on our network? A command-execution flaw is only as damaging as what the machine can touch. Ask for that answer in writing.
Fourth, does our patch process cover AI services, or only the older systems on the asset list? Check that the gateway appears in your inventory and has an owner.
A prompt template is a small program. The sandbox around it is a promise that someone has to keep patched.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: GitLab.





