Security & AI news

AI infrastructure vulnerabilities · By FireAI Security & Research Team · Published

GitLab patches critical AI Gateway flaw that lets a user escape the prompt template sandbox

GitLab fixed CVE-2026-90970, rated 9.9, in self-hosted AI Gateway versions: a user with Duo Agent Platform access could run commands via a crafted flow configuration.

A stack of data disks and the FireAI research mascot, illustrating GitLab patching a critical AI Gateway flaw that allowed a prompt template sandbox escape.

GitLab patched a critical vulnerability, tracked as CVE-2026-90970, in the self-hosted GitLab AI Gateway on 2 October 2026 [1] [2]. The Hacker News gives it a CVSS score of 9.9 and reports that a logged-in user with Duo Agent Platform access could run arbitrary commands on the gateway infrastructure [2]. The report matters to developers and teams that host their own AI tooling, including Mac users who administer such a server.

Background

An AI gateway sits between an organisation's software and the language models it uses, and applies prompt templates to the requests it forwards. A sandbox is meant to keep template content from running code on the host. GitLab operates a hosted gateway and also lets customers run their own, called a self-hosted AI Gateway [1] [2].

Findings

BleepingComputer quotes GitLab's advisory as stating that an authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution [1]. The report describes the weakness as an improper neutralization issue that requires basic user privileges [1].

GitLab released patches in versions 19.2.4, 19.3.2 and 19.4.1 [1] [2]. The Hacker News lists the affected gateway versions as 18.1.6 through 19.1.x, 19.3.0 through 19.3.1, and 19.4.0 [2]. Only organisations that run a self-hosted AI Gateway need to update; GitLab.com and GitLab Dedicated customers using GitLab-hosted gateways are already protected [2]. Docker deployments update by pulling the new image tag, and Helm deployments by changing the image settings [2].

The Hacker News reports that CISA documents no active exploitation, and that a HackerOne researcher with the handle invisiblemeerkat discovered the flaw [2]. It describes this as the second template engine weakness in the gateway rated 9.9, after a similar one patched in February 2026 [2]. BleepingComputer adds that GitLab contacted self-hosted customers before the release, and recalls a September patch for CVE-2026-85706, a maximum severity path traversal flaw that CISA added to its list of exploited vulnerabilities [1].

Implications for organisations

The flaw is in server software, not in a Mac app, and it needs an account with Duo Agent Platform access [1] [2]. A person with a Mac is affected only as an administrator of a self-hosted gateway or as a member of an organisation that runs one. The case illustrates that the layer that applies templates to model requests is a component that can run code, and is therefore a target in its own right.

Recommendations

  1. Determine whether the organisation runs a self-hosted GitLab AI Gateway; GitLab-hosted gateways need no action [2].
  2. Update to 19.2.4, 19.3.2 or 19.4.1, according to the version in use [1].
  3. Limit which accounts hold Duo Agent Platform access, because the flaw requires it.
  4. Review who may edit flow configurations, since a crafted flow configuration is the trigger described.
  5. Subscribe to the vendor security advisories for every AI component in use.

Relevance to FireAI

FireAI is a firewall for one Mac and does not protect or patch servers. On the Mac, it applies per-app rules to each connection an app opens, and the Agent profile learns the destinations an AI agent app normally contacts and flags a new one, using only host names and byte counts. A developer who connects tools to a company gateway would see that gateway as a destination in the Activity page.

FireAI does not detect this vulnerability, does not see commands run on a remote server, and does not read the inside of an encrypted connection. It cannot tell whether a gateway has been patched, and it does not prevent an authenticated user of a server from abusing a flaw in that server.

Limitations

The two sources describe the affected versions differently: BleepingComputer lists the patched versions, and The Hacker News lists affected ranges [1] [2]. This item did not fetch GitLab's own advisory, so the ranges above should be checked against it. The sources do not describe a working exploit, and the CVSS score of 9.9 is reported by The Hacker News alone [2].

Try FireAI, by HisnLabs free for 17 days.

Sources

  1. BleepingComputer, 2 October 2026: GitLab warns of critical RCE vulnerability in AI Gateway service
  2. The Hacker News, 2 October 2026: GitLab patches critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers