# GitLab patches critical AI Gateway flaw that lets a user escape the prompt template sandbox

> GitLab fixed CVE-2026-90970, rated 9.9, in self-hosted AI Gateway versions: a user with Duo Agent Platform access could run commands via a crafted flow configuration.

FireAI Security & Research Team (HisnLabs) · Published 2026-10-03
Canonical: https://hisnlabs.com/en/news/gitlab-ai-gateway-critical-flaw-prompt-template-sandbox-escape

GitLab patched a critical vulnerability, tracked as CVE-2026-90970, in the self-hosted GitLab AI Gateway on 2 October 2026 [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/) [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). The Hacker News gives it a CVSS score of 9.9 and reports that a logged-in user with Duo Agent Platform access could run arbitrary commands on the gateway infrastructure [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). The report matters to developers and teams that host their own AI tooling, including Mac users who administer such a server.

## Background

An AI gateway sits between an organisation's software and the language models it uses, and applies prompt templates to the requests it forwards. A sandbox is meant to keep template content from running code on the host. GitLab operates a hosted gateway and also lets customers run their own, called a self-hosted AI Gateway [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/) [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html).

## Findings

BleepingComputer quotes GitLab's advisory as stating that an authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/). The report describes the weakness as an improper neutralization issue that requires basic user privileges [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/).

GitLab released patches in versions 19.2.4, 19.3.2 and 19.4.1 [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/) [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). The Hacker News lists the affected gateway versions as 18.1.6 through 19.1.x, 19.3.0 through 19.3.1, and 19.4.0 [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). Only organisations that run a self-hosted AI Gateway need to update; GitLab.com and GitLab Dedicated customers using GitLab-hosted gateways are already protected [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). Docker deployments update by pulling the new image tag, and Helm deployments by changing the image settings [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html).

The Hacker News reports that CISA documents no active exploitation, and that a HackerOne researcher with the handle invisiblemeerkat discovered the flaw [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). It describes this as the second template engine weakness in the gateway rated 9.9, after a similar one patched in February 2026 [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). BleepingComputer adds that GitLab contacted self-hosted customers before the release, and recalls a September patch for CVE-2026-85706, a maximum severity path traversal flaw that CISA added to its list of exploited vulnerabilities [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/).

> FireAI, the on-device firewall for macOS developed by HisnLabs, recognises AI agent apps such as Claude Code and Cursor and flags a first-ever destination or an upload spike for review. A 17-day trial is available. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Implications for organisations

The flaw is in server software, not in a Mac app, and it needs an account with Duo Agent Platform access [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/) [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). A person with a Mac is affected only as an administrator of a self-hosted gateway or as a member of an organisation that runs one. The case illustrates that the layer that applies templates to model requests is a component that can run code, and is therefore a target in its own right.

## Recommendations

1. Determine whether the organisation runs a self-hosted GitLab AI Gateway; GitLab-hosted gateways need no action [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html).
2. Update to 19.2.4, 19.3.2 or 19.4.1, according to the version in use [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/).
3. Limit which accounts hold Duo Agent Platform access, because the flaw requires it.
4. Review who may edit flow configurations, since a crafted flow configuration is the trigger described.
5. Subscribe to the vendor security advisories for every AI component in use.

## Relevance to FireAI

FireAI is a firewall for one Mac and does not protect or patch servers. On the Mac, it applies [per-app rules](https://hisnlabs.com/en/docs/per-app-rules) to each connection an app opens, and the [Agent profile](https://hisnlabs.com/en/docs/agent-profile) learns the destinations an AI agent app normally contacts and flags a new one, using only host names and byte counts. A developer who connects tools to a company gateway would see that gateway as a destination in the [Activity](https://hisnlabs.com/en/docs/activity-and-connection-history) page.

FireAI does not detect this vulnerability, does not see commands run on a remote server, and does not read the inside of an encrypted connection. It cannot tell whether a gateway has been patched, and it does not prevent an authenticated user of a server from abusing a flaw in that server.

> On a Mac, an AI tool that reaches a new server is visible at the network layer. FireAI asks before an app contacts a destination it has no rule for, and keeps the list of what each app reached. Try it free for 17 days. [Download FireAI for Mac](https://hisnlabs.com/en/download)

## Limitations

The two sources describe the affected versions differently: BleepingComputer lists the patched versions, and The Hacker News lists affected ranges [[1]](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/) [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html). This item did not fetch GitLab's own advisory, so the ranges above should be checked against it. The sources do not describe a working exploit, and the CVSS score of 9.9 is reported by The Hacker News alone [[2]](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html).

Try [FireAI, by HisnLabs](https://hisnlabs.com/en/download) free for 17 days.

## Sources

- [BleepingComputer, 2 October 2026: GitLab warns of critical RCE vulnerability in AI Gateway service](https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/)
- [The Hacker News, 2 October 2026: GitLab patches critical 9.9 AI Gateway flaw allowing command execution on self-hosted servers](https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html)
