RC RANDOM CHAOS

GitLab AI Gateway sandbox escape

GitLab's critical CVE-2026-90970 lets an authenticated Duo user escape the AI Gateway prompt sandbox and run arbitrary commands. Self-hosted operators must patch now.

· 3 min read
GitLab AI Gateway sandbox escape

An authenticated GitLab user with Duo Agent Platform access could escape the AI Gateway’s prompt template sandbox with a specially crafted flow configuration and run arbitrary commands on the host. That is CVE-2026-90970, which GitLab rated critical and told self-hosted customers to patch immediately in a Friday advisory.

AI Gateway is the service behind GitLab Duo, the AI-native features. GitLab runs its own cloud instance for GitLab.com, GitLab Self-Managed, and GitLab Dedicated, and that instance is already fixed. GitLab says those customers need to do nothing. The exposure is for anyone running their own copy through GitLab Duo Self-Hosted, which is only available on Self-Managed. If you deployed an AI Gateway yourself, the patch is yours to apply.

GitLab attributes the flaw to an improper neutralization weakness. The shape of it is familiar from server-side template injection: a flow configuration supplied by the user is handled by the prompt template engine, which is supposed to confine that input to a sandbox, and a crafted configuration breaks out of the sandbox into command execution on the Gateway. The prerequisites are modest. GitLab’s description calls for an authenticated user with basic privileges plus Duo Agent Platform access, not an administrator and not an external attacker. On an instance where developers can author Duo flows, that is a large set of people, and the payoff is arbitrary command execution on the AI Gateway, a service you host yourself on Self-Managed.

The fixed versions are 19.2.4, 19.3.2, and 19.4.1, each covering a different release line. Pick the one that matches your installed version and upgrade. GitLab says it contacted Self-Hosted AI Gateway operators directly before publishing the advisory, so some teams will already have the heads-up. If you are not sure whether you run a self-hosted Gateway, that uncertainty is itself worth resolving today, because the GitLab-hosted path and the self-hosted path have opposite answers here.

This lands weeks after GitLab patched CVE-2026-85706, a maximum-severity path traversal in Community and Enterprise Edition that let unauthenticated attackers read credentials and other secrets off vulnerable servers. CISA added that one to its Known Exploited Vulnerabilities catalog a day after the fix and, under Binding Operational Directive 26-04, gave federal agencies three days to remediate. There is no indication in the advisory that CVE-2026-90970 is being exploited in the wild, but the recent history is the reason to move quickly: since November 2021 CISA has flagged five GitLab vulnerabilities as abused in the wild, one of them by ransomware groups. GitLab’s platform has over 30 million registered users and runs at more than half of the Fortune 100, including Nvidia, Lockheed Martin, T-Mobile, Goldman Sachs, Airbus, and UBS, so proof-of-concept work tends to follow disclosure fast.

The broader point for anyone wiring LLM features into their own infrastructure is that the prompt template sandbox is a trust boundary, and this is what it looks like when one leaks. A flow configuration is attacker-controlled input the moment a non-privileged user can author it. If that input reaches a template engine with any evaluation capability, sandbox escape to RCE is the default failure mode, not an exotic one. Treat Duo flow definitions, and any equivalent in your own stack, as untrusted code that happens to be written by authenticated users.

Patch the self-hosted AI Gateway to 19.2.4, 19.3.2, or 19.4.1 now; GitLab-hosted Gateway users are already covered.

Share

Keep Reading

Latest on the Wire

Full wire →

New signal daily · RSS

Stay in the loop

New writing delivered when it's ready. No schedule, no spam.