ZERO
Back
vulnerabilityCVE-2026-90970

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

An improper neutralization issue in a custom flow prompt template in GitLab Self-Hosted AI Gateway could allow an authenticated user with Duo Agent Platform access to escape the prompt-template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway. GitLab lists affected versions as all versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1; GitLab-hosted AI Gateways were already fixed.

Severity
9.9Critical
Exploitation evidence
None confirmed
Remediation
Fixed in 19.2.4

Affected software

CVSS (Common Vulnerability Scoring System)

Preferred assessment

Vector

Attack vector

Attack complexity

Privileges required

User interaction

Scope

Confidentiality impact

Integrity impact

Availability impact

Source assessments

EPSS (Exploit Prediction Scoring System)

Probability

Percentile

Model

Preferred remediation

Action