뉴스로 돌아가기
보안AI Understanding 브리핑

GitLab은 중요한 AI Gateway RCE 취약점을 패치합니다.

GitLab은 템플릿 주입을 통해 샌드박스 탈출을 허용하는 AI 게이트웨이의 중요한 원격 코드 실행 결함인 CVE-2026-90970에 대한 패치를 출시했습니다.

4 min readRead the linked source
Source-provided image accompanying GitLab patches critical AI Gateway RCE vulnerability
소스 참조녹음된 소스
출판사
forkast.news
소스 링크
forkast.newshttps://forkast.news/gitlab-patches-critical-ai-gateway-rce-vulnerability-prompt-template-sandbox-escape-rated-cvss-9-9/
소스 유형
연결된 소스 — 기본 소스 상태가 설정되지 않았습니다.
맥락60초 안에 이해하세요

여기서 시작하세요

주요 용어

AI 에이전트
종종 도구와 메모리를 사용하여 목표를 달성하기 위해 관찰하고, 추론하고, 조치를 취할 수 있는 소프트웨어 시스템입니다.
자신을 테스트해 보세요AI 에이전트 퀴즈

무슨 일이 일어났나요?

GitLab released security patches for CVE-2026-90970, a critical vulnerability in its AI Gateway component. The flaw, rated CVSS 9.9, allows authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the host system by exploiting insufficient sanitization of Jinja2-style template placeholders. This is reported as the first critical RCE vulnerability identified in an AI-specific infrastructure component. Self-hosted users must update to versions 19.2.4, 19.3.2, or 19.4.1, while GitLab-hosted instances have already been patched. No evidence of active exploitation or public proof-of-concept exists as of October 3, 2026.

GitLab has released patches for CVE-2026-90970, a critical vulnerability affecting the GitLab AI Gateway. According to forkast.news, the flaw carries a CVSS score of 9.9 and allows an authenticated user with Duo Agent Platform access to achieve arbitrary command execution on the underlying host. The vulnerability is classified under CWE-1336 and stems from insufficient sanitization of user-supplied flow configuration data.

The technical mechanism involves the AI Gateway's use of Jinja2-style template placeholders to process configurations. Because the input is not properly neutralized, an attacker can manipulate the template engine to perform a sandbox escape, breaking out of the intended execution context to execute commands directly on the host operating system. The source notes this is the first critical remote code execution vulnerability identified in an AI-specific infrastructure component.

For organizations operating self-hosted instances, the implications are significant because the AI Gateway acts as a central hub holding sensitive JWT signing keys and managing connections to internal GitLab instances and external AI model providers. GitLab-hosted instances have been patched, but self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1. There is no available workaround, and no reliable method exists to determine whether a gateway was compromised before patching.

The source reports that as of October 3, 2026, there is no evidence of exploitation in the wild and no public proof-of-concept exploit has been published. CISA assessed the exploitation status as none on October 2. However, the source emphasizes that the absence of a known exploit does not reduce the severity for self-hosted environments, making the update the only effective remediation.

소스 세부정보: forkast.news ↗

왜 중요한가요?

This incident highlights a persistent security weakness in infrastructure, specifically the failure to properly isolate template engines from user-controllable inputs. Because the AI Gateway manages sensitive JWT signing keys and connections to external AI model providers, a compromise could grant attackers control over an organization's AI workflows and authentication tokens. The recurrence of this vulnerability class in the same component within eight months underscores the need for robust sandboxing in AI deployment environments.

The vulnerability fits a 'trust-through-defaults' pattern where components are deployed with insufficient security boundaries around user-controllable inputs. The source links this to recent incidents including the OpenAI Misalignment Portal DNS sandbox escape and the DIVD Zammad breach, suggesting a broader trend of security failures in platforms.

The recurrence of this specific vulnerability class is notable. In February 2026, a previous vulnerability (CVE-2026-1868) was identified in the same Duo Workflow Service component, also involving CWE-1336 and carrying a CVSS 9.9 rating. This indicates that the template-engine sandbox boundary remains a persistent point of failure for platforms.

A compromise of the AI Gateway could give an attacker control over an organization’s AI-integrated workflows and authentication tokens. This is particularly concerning because the component manages connections to external AI model providers, potentially exposing sensitive data or enabling lateral movement within an organization's infrastructure.

Interactive Mechanism

대화형 메커니즘: 실제로 작동하는 방식

이 개발의 이면에 있는 기본 기술을 대화식으로 살펴보세요.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
대화형 개념 확인+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

다음에 무엇을 볼 것인가

Monitor for any public disclosure of proof-of-concept exploits or evidence of in-the-wild exploitation. Track whether other AI infrastructure vendors address similar template-engine sandboxing issues. Observe if CISA or other regulatory bodies issue further guidance on securing platforms.

Security professionals should focus on the template-engine sandbox boundary and the agent capability and tool boundary, which governs how agents interact with external systems. The source suggests that the rate at which AI infrastructure vulnerabilities are being identified is accelerating.

Organizations should verify their patch status immediately, as there is no reliable method to detect prior compromise. The recurrence rate of high-severity vulnerabilities in the same component should drive the timeline for self-hosted operators to apply updates.

Watch for further disclosures from CISA or other security agencies regarding the exploitation status of this vulnerability, as well as any similar vulnerabilities reported in other AI infrastructure components.

관련 가이드 및 퀴즈

AI 에이전트AI 윤리AI 모델 설명알고 있는 내용을 테스트해 보세요. 무료 AI 퀴즈를 시도해 보세요.용어집에서 AI 용어를 찾아보세요.AI 규제 추적기를 따르세요
이것이 유용하다고 생각하시나요?