GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3… (CVE-2026-90970)
A critical vulnerability (CVE-2026-90970) in the GitLab AI Gateway component affects multiple versions prior to 19.2.4, 19.3.2, and 19.4.1. This flaw allows an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a crafted flow configuration, leading to arbitrary command execution on the AI Gateway.
AI Analysis
Technical Summary
The GitLab AI Gateway component contains a vulnerability that permits an authenticated user with Duo Agent Platform access to bypass the prompt template sandbox restrictions by using a specially crafted flow configuration. This vulnerability affects all versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Successful exploitation results in arbitrary command execution on the AI Gateway, posing a critical security risk. The CVSS v3.1 score is 9.9, indicating high attack vector and impact.
Potential Impact
An attacker with authenticated Duo Agent Platform access can execute arbitrary commands on the AI Gateway, potentially leading to full compromise of the AI Gateway component. This impacts confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
GitLab has remediated this vulnerability in versions 19.2.4, 19.3.2, and 19.4.1 and later. Users should upgrade to these fixed versions or later to mitigate the risk. Since this is not a cloud service, patching the affected AI Gateway component is required. Patch status is confirmed by the vendor advisory.
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3… (CVE-2026-90970)
Description
A critical vulnerability (CVE-2026-90970) in the GitLab AI Gateway component affects multiple versions prior to 19.2.4, 19.3.2, and 19.4.1. This flaw allows an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a crafted flow configuration, leading to arbitrary command execution on the AI Gateway.
CVSS v3.1
Score 9.9critical
Affected software
pkg:github/gitlab-org/gitlabRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The GitLab AI Gateway component contains a vulnerability that permits an authenticated user with Duo Agent Platform access to bypass the prompt template sandbox restrictions by using a specially crafted flow configuration. This vulnerability affects all versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Successful exploitation results in arbitrary command execution on the AI Gateway, posing a critical security risk. The CVSS v3.1 score is 9.9, indicating high attack vector and impact.
Potential Impact
An attacker with authenticated Duo Agent Platform access can execute arbitrary commands on the AI Gateway, potentially leading to full compromise of the AI Gateway component. This impacts confidentiality, integrity, and availability of the affected system.
Mitigation Recommendations
GitLab has remediated this vulnerability in versions 19.2.4, 19.3.2, and 19.4.1 and later. Users should upgrade to these fixed versions or later to mitigate the risk. Since this is not a cloud service, patching the affected AI Gateway component is required. Patch status is confirmed by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5295-vp56-jghq
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-90970"]
- Database Specific Severity
- CRITICAL
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6abfee74a43b0b3b89e5436b
Added to database: 10/02/2026, 17:48:36 UTC
Last enriched: 10/02/2026, 17:50:52 UTC
Last updated: 10/03/2026, 04:45:56 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.