GitLab has released security updates for a critical flaw in the GitLab AI Gateway. The bug is tracked as CVE-2026-90970 and scored CVSS 9.9, according to reporting from Cybersecurity News and SC World. Some outlets list a different CVE identifier for the same issue, so confirm against GitLab's own advisory before filing tickets.
The flaw sits in how the gateway handles custom flow prompt templates. An authenticated user with Duo Agent Platform access can submit a crafted flow configuration that escapes the prompt template sandbox. Reporting describes the mechanism as Jinja2 template injection. The result is arbitrary command execution on the AI Gateway host.
Why it matters: the attacker needs a valid account, but not an administrator one. The AI Gateway typically sits close to source code, model credentials and CI context. A sandbox escape there turns any low-privilege Duo user into code execution on a service that holds those secrets. No in-the-wild exploitation has been reported in the sources we reviewed.
Affected versions: AI Gateway from 18.1.6 up to, but excluding, 19.2.4. The 19.3 branch before 19.3.2. The 19.4 branch before 19.4.1. GitLab says its managed services are already patched. Self-hosted gateways are exposed.
What to do. Upgrade self-hosted AI Gateways to 19.2.4, 19.3.2 or 19.4.1, as appropriate. Until patched, restrict who has Duo Agent Platform access and review custom flow configurations for unexpected template expressions. Check gateway hosts for unexpected child processes and outbound connections. Rotate any credentials stored on a gateway you cannot confirm was clean.






























