What happened
GitLab has issued security patches for a critical vulnerability, tracked as CVE-2026-90970, affecting its self-hosted AI Gateway service. The vulnerability, which carries a CVSS 3.1 score of 9.9, stems from a flaw in how the service handles custom workflow settings and isolates templates within the Duo Agent Platform. By crafting specific workflow configurations, an authenticated user with access to the Duo Agent Platform could potentially bypass environment isolation and execute arbitrary commands on the host server.
GitLab identified a critical vulnerability, CVE-2026-90970, in its AI Gateway service, which facilitates the connection between GitLab Duo functionality and AI models. The vulnerability is classified as a mishandling of special elements within a template engine, allowing for an escape from the isolated environment.
The flaw specifically impacts self-hosted installations of the AI Gateway. Users of GitLab-hosted AI Gateway services are not required to take action, as the company has already applied the necessary updates to its managed infrastructure.
Exploitation of this vulnerability is not anonymous; it requires an attacker to possess an account with authorized access to the Duo Agent Platform. Once inside, an attacker can leverage the flaw to execute arbitrary commands on the underlying host server.
GitLab has released patches in versions 19.2.4, 19.3.2, and 19.4.1. The vulnerability affects versions 18.1.6 through 19.2.3, as well as specific sub-versions within the 19.3 and 19.4 branches.
Why it matters
This vulnerability is significant because it allows for remote code execution on infrastructure hosting AI-driven development tools. While the exploit requires existing access to the Duo Agent Platform, the potential for command execution poses a severe risk to the integrity of self-hosted GitLab environments. Because the flaw resides in the AI Gateway's template engine, it highlights the security challenges inherent in integrating complex AI workflows into existing software development lifecycles, particularly when those workflows involve custom, user-defined logic.
The 9.9 CVSS score underscores the severity of the risk, as it allows for unauthorized command execution on servers that often hold sensitive source code and development data.
The incident demonstrates the increased attack surface introduced by AI-integrated development platforms. As organizations adopt AI agents to automate workflows, the security of the underlying gateway and -handling mechanisms becomes a critical component of the overall security posture.
There are currently no reports of this vulnerability being exploited in the wild, according to information provided by GitLab and the NVD. However, the technical feasibility of the exploit necessitates immediate remediation for all affected self-hosted environments.
Interactive Mechanism: How It Actually Works
Explore the underlying technology behind this development interactively.
crm_get_transaction(id='4092').An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?
What to watch next
Administrators of self-hosted GitLab instances must verify their deployment topology to determine if they are running an affected version of the AI Gateway. Organizations should prioritize patching to versions 19.2.4, 19.3.2, or 19.4.1, depending on their current branch. Security teams should also audit permissions for the Duo Agent Platform to ensure that only trusted users can create or modify workflows until patches are fully applied.
Administrators should perform an inventory of their GitLab infrastructure to identify all self-hosted AI Gateway instances and confirm their current version numbers.
In environments where immediate patching is not feasible, administrators are advised to restrict access to the Duo Agent Platform to a limited set of trusted users to mitigate the risk of exploitation.
Security teams should monitor logs for unusual workflow modifications or unexpected command execution patterns that might indicate an attempt to leverage the vulnerability.
The distinction between the main GitLab service and the AI Gateway is vital; administrators must ensure that the specific AI Gateway component is updated, as a standard platform update may not be sufficient.