vulnerabilityCVE-2026-90970
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
An improper neutralization issue in a custom flow prompt template in GitLab Self-Hosted AI Gateway could allow an authenticated user with Duo Agent Platform access to escape the prompt-template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway. GitLab lists affected versions as all versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1; GitLab-hosted AI Gateways were already fixed.
Severity
9.9Critical
Exploitation evidence
None confirmed
Remediation
Fixed in 19.2.4
Affected software
| Software | Affected versions | Fixed in | Sources |
|---|---|---|---|
CVSS (Common Vulnerability Scoring System)
Preferred assessment
Vector
Attack vector
Attack complexity
Privileges required
User interaction
Scope
Confidentiality impact
Integrity impact
Availability impact
Source assessments
EPSS (Exploit Prediction Scoring System)
Probability
Percentile
Model
Preferred remediation
Action