Tillbaka till Nyheter
SäkerhetAI Understanding genomgång

GitLab korrigerar kritisk AI Gateway RCE-sårbarhet

GitLab släppte patchar för CVE-2026-90970, ett kritiskt fel vid exekvering av fjärrkod i dess AI Gateway som tillåter sandlådeflykt via mallinjektion.

4 min readRead the linked source
Source-provided image accompanying GitLab patches critical AI Gateway RCE vulnerability
KällhänvisningKälla inspelad
Förläggare
forkast.news
Källlänk
forkast.newshttps://forkast.news/gitlab-patches-critical-ai-gateway-rce-vulnerability-prompt-template-sandbox-escape-rated-cvss-9-9/
Källtyp
Länkad källa – status för primär källa har inte fastställts.
SammanhangFörstå detta på 60 sekunder

Börja här

Nyckeltermer

AI-agent
Ett mjukvarusystem som kan observera, resonera och vidta åtgärder för att uppnå ett mål, ofta med hjälp av verktyg och minne.
Testa dig självAI Agents Quiz

Vad hände

GitLab released security patches for CVE-2026-90970, a critical vulnerability in its AI Gateway component. The flaw, rated CVSS 9.9, allows authenticated users with access to the Duo Agent Platform to execute arbitrary commands on the host system by exploiting insufficient sanitization of Jinja2-style template placeholders. This is reported as the first critical RCE vulnerability identified in an AI-specific infrastructure component. Self-hosted users must update to versions 19.2.4, 19.3.2, or 19.4.1, while GitLab-hosted instances have already been patched. No evidence of active exploitation or public proof-of-concept exists as of October 3, 2026.

GitLab has released patches for CVE-2026-90970, a critical vulnerability affecting the GitLab AI Gateway. According to forkast.news, the flaw carries a CVSS score of 9.9 and allows an authenticated user with Duo Agent Platform access to achieve arbitrary command execution on the underlying host. The vulnerability is classified under CWE-1336 and stems from insufficient sanitization of user-supplied flow configuration data.

The technical mechanism involves the AI Gateway's use of Jinja2-style template placeholders to process configurations. Because the input is not properly neutralized, an attacker can manipulate the template engine to perform a sandbox escape, breaking out of the intended execution context to execute commands directly on the host operating system. The source notes this is the first critical remote code execution vulnerability identified in an AI-specific infrastructure component.

For organizations operating self-hosted instances, the implications are significant because the AI Gateway acts as a central hub holding sensitive JWT signing keys and managing connections to internal GitLab instances and external AI model providers. GitLab-hosted instances have been patched, but self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1. There is no available workaround, and no reliable method exists to determine whether a gateway was compromised before patching.

The source reports that as of October 3, 2026, there is no evidence of exploitation in the wild and no public proof-of-concept exploit has been published. CISA assessed the exploitation status as none on October 2. However, the source emphasizes that the absence of a known exploit does not reduce the severity for self-hosted environments, making the update the only effective remediation.

Källinformation: forkast.news ↗

Varför det spelar roll

This incident highlights a persistent security weakness in infrastructure, specifically the failure to properly isolate template engines from user-controllable inputs. Because the AI Gateway manages sensitive JWT signing keys and connections to external AI model providers, a compromise could grant attackers control over an organization's AI workflows and authentication tokens. The recurrence of this vulnerability class in the same component within eight months underscores the need for robust sandboxing in AI deployment environments.

The vulnerability fits a 'trust-through-defaults' pattern where components are deployed with insufficient security boundaries around user-controllable inputs. The source links this to recent incidents including the OpenAI Misalignment Portal DNS sandbox escape and the DIVD Zammad breach, suggesting a broader trend of security failures in platforms.

The recurrence of this specific vulnerability class is notable. In February 2026, a previous vulnerability (CVE-2026-1868) was identified in the same Duo Workflow Service component, also involving CWE-1336 and carrying a CVSS 9.9 rating. This indicates that the template-engine sandbox boundary remains a persistent point of failure for platforms.

A compromise of the AI Gateway could give an attacker control over an organization’s AI-integrated workflows and authentication tokens. This is particularly concerning because the component manages connections to external AI model providers, potentially exposing sensitive data or enabling lateral movement within an organization's infrastructure.

Interactive Mechanism

Interaktiv mekanism: hur det faktiskt fungerar

Utforska den underliggande tekniken bakom denna utveckling interaktivt.

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
Interaktiv konceptkontroll+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

Vad du ska titta på härnäst

Monitor for any public disclosure of proof-of-concept exploits or evidence of in-the-wild exploitation. Track whether other AI infrastructure vendors address similar template-engine sandboxing issues. Observe if CISA or other regulatory bodies issue further guidance on securing platforms.

Security professionals should focus on the template-engine sandbox boundary and the agent capability and tool boundary, which governs how agents interact with external systems. The source suggests that the rate at which AI infrastructure vulnerabilities are being identified is accelerating.

Organizations should verify their patch status immediately, as there is no reliable method to detect prior compromise. The recurrence rate of high-severity vulnerabilities in the same component should drive the timeline for self-hosted operators to apply updates.

Watch for further disclosures from CISA or other security agencies regarding the exploitation status of this vulnerability, as well as any similar vulnerabilities reported in other AI infrastructure components.

Relaterade guider och frågesporter

AI-agenterAI-etikAI-modeller förklarasTesta vad du vet – prova ett gratis AI-quizSlå upp en AI-term i vår ordlistaFölj AI-regleringen
Hittade du detta användbart?