
GitLab AI Gateway CVE-2026-90970: Who Needs to Patch
Published by AINave Editorial
GitLab’s CVE-2026-90970 is a critical AI Gateway flaw with a specific route to command execution: an authenticated user with Duo Agent Platform access could exploit a specially crafted flow configuration to escape the prompt-template sandbox. GitLab advises customers running Self-Hosted AI Gateway on GitLab Self-Managed to update immediately, while saying users of its hosted gateway are already protected.
The risk depends on how AI Gateway is deployed
AI Gateway provides access to AI-native GitLab Duo features. GitLab operates a hosted instance used by GitLab.com, GitLab Self-Managed and GitLab Dedicated, but customers can also deploy their own AI Gateway through GitLab Duo Self-Hosted.
That distinction changes who needs to act. GitLab’s guidance targets customers with their own Self-Hosted AI Gateway installations on GitLab Self-Managed; the company says customers using a GitLab-hosted AI Gateway do not need to take action. The advisory describes a vulnerability in the gateway service, not a blanket compromise of every GitLab installation.
The exploit requires access, then crosses a sandbox boundary
GitLab describes CVE-2026-90970 as an improper-neutralization weakness. Under certain conditions, an authenticated user who has Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt-template sandbox and run arbitrary commands on the AI Gateway.
The access requirement matters: the reported route is not unauthenticated remote code execution. But a sandbox escape that reaches command execution still makes the issue consequential for operators of affected self-hosted gateways. The advisory does not establish that attackers have exploited this flaw in the wild.
Update self-hosted instances to a fixed release
GitLab released AI Gateway versions 19.2.4, 19.3.2 and 19.4.1 to address the vulnerability. It strongly recommends that GitLab Self-Managed customers running Self-Hosted AI Gateway update to one of those versions immediately. GitLab also said it contacted self-hosted customers before publishing the advisory.
For teams checking their exposure, the key first distinction is whether they run a self-hosted gateway or use GitLab’s hosted service. The patch guidance applies to the former; the company says the latter is already protected. That deployment split makes the advisory more targeted than a general GitLab platform update, while leaving self-hosted gateway operators with a clear, urgent action.






















