Skip to main content
Vulnerability Database/CVE-2026-90970

CVE-2026-90970: GitLab AI Gateway RCE Vulnerability

CVE-2026-90970 is a remote code execution vulnerability in GitLab AI Gateway that allows authenticated users to escape prompt template sandboxes and execute arbitrary commands. This article covers technical details, affected versions, and mitigation strategies.

Published:

CVE-2026-90970 Overview

GitLab has patched a sandbox escape vulnerability in the GitLab AI Gateway component. The flaw affects AI Gateway versions 18.1.6 through 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. An authenticated user with Duo Agent Platform access can craft a malicious flow configuration to break out of the prompt template sandbox. Successful exploitation results in arbitrary command execution on the AI Gateway host. The vulnerability is tracked under [CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine].

Critical Impact

Authenticated attackers with Duo Agent Platform access can achieve arbitrary command execution on the AI Gateway, compromising the integrity and confidentiality of connected GitLab environments.

Affected Products

  • GitLab AI Gateway versions 18.1.6 through 19.2.3
  • GitLab AI Gateway 19.3 before 19.3.2
  • GitLab AI Gateway 19.4 before 19.4.1

Discovery Timeline

  • 2026-10-02 - CVE-2026-90970 published to NVD
  • 2026-10-02 - Last updated in NVD database

Technical Details for CVE-2026-90970

Vulnerability Analysis

The GitLab AI Gateway processes flow configurations submitted by users with Duo Agent Platform privileges. These flows reference prompt templates rendered by a template engine. The engine fails to neutralize special syntax elements inside attacker-controlled flow fields. An authenticated user can supply template directives that execute outside the intended sandbox. The scope change (S:C) in the CVSS vector reflects that execution impacts resources beyond the vulnerable component, extending the blast radius to the hosting environment and connected services.

Root Cause

The root cause is a template engine injection flaw classified as [CWE-1336]. The AI Gateway treats portions of a user-supplied flow configuration as trusted template input. When the template is rendered, embedded expressions are evaluated in a context that permits access to host functions. The sandbox boundary intended to restrict template evaluation to safe operations does not block these expressions. See the GitLab Work Item #628842 for vendor details.

Attack Vector

Exploitation requires network access to the AI Gateway and valid credentials with Duo Agent Platform access. The attacker submits a flow configuration containing a specially crafted prompt template. When the AI Gateway renders the template, injected directives escape the sandbox and invoke operating system commands under the AI Gateway service account. No user interaction is required beyond the attacker's own authenticated session.

No public exploit code or proof-of-concept has been published. Technical specifics are described in the vendor advisory referenced above.

Detection Methods for CVE-2026-90970

Indicators of Compromise

  • Unexpected child processes spawned by the AI Gateway service, such as shells (sh, bash), interpreters (python, node), or network utilities (curl, wget, nc).
  • Anomalous outbound network connections initiated from the AI Gateway host to unknown destinations.
  • Flow configuration submissions from Duo Agent Platform users containing unusual template syntax, control characters, or references to runtime builtins.

Detection Strategies

  • Monitor AI Gateway process trees for deviations from the baseline set of child processes.
  • Inspect audit logs for Duo Agent Platform flow configuration create and update events, correlating against user risk scores.
  • Alert on file writes to sensitive paths (/etc, /var, home directories) originating from the AI Gateway process.

Monitoring Recommendations

  • Enable verbose logging for AI Gateway prompt template rendering and ship logs to a central SIEM for retention and correlation.
  • Track authentication events for Duo Agent Platform roles and flag privilege changes.
  • Baseline normal AI Gateway egress traffic and alert on new destinations or protocol anomalies.

How to Mitigate CVE-2026-90970

Immediate Actions Required

  • Upgrade GitLab AI Gateway to version 19.2.4, 19.3.2, 19.4.1, or later as applicable to your release branch.
  • Audit all Duo Agent Platform user accounts and revoke access for users who do not require it.
  • Review historical flow configurations submitted since deployment of affected versions for suspicious template content.

Patch Information

GitLab released fixed versions 19.2.4, 19.3.2, and 19.4.1 of the AI Gateway. Refer to the GitLab Work Item #628842 for the official remediation and upgrade instructions.

Workarounds

  • Disable the Duo Agent Platform feature in the AI Gateway configuration until the patch can be applied.
  • Restrict network access to the AI Gateway to trusted administrative subnets.
  • Run the AI Gateway service under a least-privilege account with no shell and restricted filesystem permissions to limit post-exploitation impact.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.