GitLab warns of critical RCE vulnerability in AI Gateway service

Customers urged to patch self-hosted instances immediately

By LineZotpaper
Published
Read Time2 min
GitLab has warned customers to patch a critical vulnerability in its AI Gateway service that could allow attackers with basic privileges to execute arbitrary commands on vulnerable instances. The flaw affects self-hosted AI Gateway installations; GitLab-hosted instances are already protected.

GitLab released an advisory on Friday warning of a critical remote code execution vulnerability in its AI Gateway service, tracked as CVE-2026-90970. The vulnerability stems from an improper neutralisation weakness that could let an authenticated user with Duo Agent Platform access escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway.

The AI Gateway provides access to GitLab Duo AI features. While GitLab operates a cloud-based instance for GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users can also deploy their own self-hosted instance through GitLab Duo Self-Hosted.

GitLab has released versions 19.2.4, 19.3.2, and 19.4.1 to address the issue for Self-Hosted AI Gateway users. The company said it conducted targeted outreach to affected customers before the disclosure and strongly recommends upgrading vulnerable instances as soon as possible. Customers using a GitLab-hosted AI Gateway do not need to take action.

The advisory follows a maximum severity path traversal vulnerability patched last month (CVE-2026-85706) that allowed unauthenticated attackers to read sensitive data. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) later added that flaw to its list of actively exploited vulnerabilities.

§

Analysis

Why This Matters

  • Self-hosted GitLab AI Gateway users face a critical risk of remote code execution if not patched promptly.
  • The vulnerability highlights the added security burden of running AI infrastructure in-house, as opposed to using a managed service.
  • This is the second critical GitLab flaw in weeks, raising questions about the security posture of AI-related components.

Background

The GitLab AI Gateway is a service that provides access to GitLab Duo, a suite of AI-powered features for code review, summarisation, and other development tasks. Organisations that self-host GitLab can also self-host the AI Gateway to keep data within their infrastructure. The vulnerability in question allows an authenticated attacker with access to the Duo Agent Platform to escape a sandbox and execute arbitrary commands.

Key Perspectives

GitLab: The company has released patches and conducted targeted outreach to self-hosted customers, urging immediate upgrades. It states that GitLab-hosted AI Gateway instances are not affected.

Security community: Flaws in AI infrastructure are a growing concern. This vulnerability's critical severity and the potential for exploitation make timely patching essential.

Self-hosted customers: Those running their own AI Gateway must weigh the disruption of a patch deployment against the risk of compromise.

What to Watch

  • Adoption rate of the patched versions among self-hosted users.
  • Any reports of active exploitation of CVE-2026-90970.
  • Whether CISA adds this vulnerability to its known exploited flaws catalog, as it did with the previous GitLab flaw.

Sources

Zotpaper

Written by software from the reporting listed above, scored by an automated standards desk, and published without a person reading it first. If something here is wrong, tell the editor and it will be put right.