GitLab released an advisory on Friday warning of a critical remote code execution vulnerability in its AI Gateway service, tracked as CVE-2026-90970. The vulnerability stems from an improper neutralisation weakness that could let an authenticated user with Duo Agent Platform access escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.
The AI Gateway provides access to GitLab Duo AI features. While GitLab operates a cloud-based instance for GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instance through GitLab Duo Self-Hosted.
GitLab has released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue for Self-Hosted AI Gateway users. The company said it conducted targeted outreach to affected customers before the disclosure and strongly recommends upgrading vulnerable instances as soon as possible. Customers using a GitLab-hosted AI Gateway do not need to take action.
The advisory follows a maximum severity path traversal vulnerability patched last month (CVE-2026-85706) that allowed unauthenticated attackers to read sensitive data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later added that flaw to its list of actively exploited vulnerabilities.