SecPod

Learn Search

Search across all Learn content

← Back to Security Research
CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

CVE-2026-90970: GitLab Strengthens AI Gateway Security Following Critical Vulnerability

Oct 5, 2026By Padmashree P

CVE-2026-90970 is a vulnerability in the GitLab AI Gateway that stems from improper handling of custom flow prompt templates used by the Duo Agent Platform. The flaw can allow specially crafted template content to escape the restrictions of the prompt template sandbox, which is intended to prevent untrusted template logic from interacting with the underlying execution environment. The issue is particularly significant for organizations operating Self-Hosted AI Gateway deployments because exploitation takes place within infrastructure controlled by the organization.

Under certain conditions, an authenticated user with access to the Duo Agent Platform could submit a specially crafted flow configuration containing malicious template elements. Improper processing of these elements could allow the attacker to break out of the security restrictions imposed by the prompt template sandbox. Successful exploitation could result in arbitrary command execution on the AI Gateway, potentially giving the attacker access to resources and sensitive information available to the gateway process. Depending on the gateway's privileges and deployment configuration, compromise could affect the confidentiality, integrity, and availability of the service and resources accessible from its execution environment.

Vulnerability Details

CVE ID Severity CVSS Score EPSS Score Impact
CVE-2026-90970 Critical 9.9 0.94% Arbitrary Command Execution

Technical Analysis

The GitLab AI Gateway operates as an intermediary between GitLab's AI-powered functionality and the underlying large language models. It handles requests originating from GitLab, performs AI-related processing and prompt preparation, and communicates with configured model providers. GitLab supports both hosted and self-hosted AI Gateway deployments, allowing organizations to operate the gateway within their own infrastructure when required.

The vulnerability results from improper neutralization of special elements used within a template engine. When attacker-controlled data from a custom flow configuration reaches the vulnerable template-processing mechanism, specially constructed template elements may not be sufficiently sanitized or constrained before evaluation. This weakness is classified as CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine.

An authenticated user with access to the Duo Agent Platform could exploit this weakness by creating a malicious flow configuration designed to interfere with template evaluation. Under the required conditions, the crafted configuration could escape the intended prompt template sandbox, crossing the security boundary intended to restrict what a prompt template can execute or access.

Impact

  1. Arbitrary Command Execution: Successful exploitation could allow an authenticated attacker to escape the prompt template sandbox and execute arbitrary commands on the affected AI Gateway.
  2. AI Gateway Compromise: Command execution could provide an attacker with a foothold on infrastructure hosting the GitLab Self-Hosted AI Gateway.
  3. Sensitive Information Exposure: A compromised gateway could expose information accessible to the AI Gateway process, depending on the deployment configuration and privileges assigned to the service.
  4. Authentication Material at Risk: Sensitive authentication-related material accessible from the compromised gateway environment could potentially be exposed.

Affected Versions

Affected GitLab AI Gateway Version Fixed Version
18.1.6 through 19.2.3 19.2.4
19.3.0 through 19.3.1 19.3.2
19.4.0 19.4.1

MITRE ATT&CK Mapping

Tactic Technique Technique ID Description
Initial Access Exploit Public-Facing Application T1190 An authenticated attacker with access to the Duo Agent Platform could exploit the vulnerable GitLab Self-Hosted AI Gateway using a specially crafted flow configuration that triggers the prompt template sandbox escape.
Execution Command and Scripting Interpreter T1059 Successful exploitation of CVE-2026-90970 can result in arbitrary command execution within the context of the affected GitLab AI Gateway service.

Mitigation

  1. Upgrade the GitLab Self-Hosted AI Gateway: Organizations running affected installations should upgrade to 19.2.4, 19.3.2, 19.4.1, or a later supported release containing the security fix.
  2. Identify Self-Hosted AI Gateway Deployments: Determine whether GitLab environments use a GitLab-hosted or Self-Hosted AI Gateway and prioritize affected self-hosted installations.
  3. Review Duo Agent Platform Access: Review accounts with access to the Duo Agent Platform and remove unnecessary permissions to reduce the number of users capable of reaching the vulnerable functionality.
  4. Review Custom Flow Configurations: Examine custom flows for unexpected or unauthorized configurations, particularly configurations created or modified by unusual accounts.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files
Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

CVE Research

Open Door: Critical FortiMail Zero-Day Exploited to Write Arbitrary Files

Fortinet has disclosed CVE-2026-104286, a critical unauthenticated path traversal and NULL-byte handling vulnerability in FortiMail that allows arbitrary file writes via crafted HTTP or HTTPS requests. The issue is reported as exploited in the wild and is listed in the CISA KEV catalog. This article covers impact, affected versions, workarounds, fixed-build guidance, and indicators of compromise.

Oct 5, 2026

Open WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels
WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

CVE Research

WHIPSHOT and SLAPSHOT: Citrix NetScaler Zero-Days Exploited to Plant Root Web Shells and Internal Tunnels

Oct 1, 2026

Open OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure
OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

CVE Research

OpenSSL’s DTLS State Handling Error Opens the Door to Heap Data Exposure

Oct 1, 2026

Open Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions
Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

CVE Research

Patch Analysis & Exploitation Timeline: Critical WSO2 and Adobe Flaws Show 1-Day vs. 133-Day Exploitation Window , September 24, 2026 KEV Additions

Two critical vulnerabilities added to CISA KEV on September 24, 2026 reveal sharply different exploitation timelines. CVE-2026-71362 saw publicly documented exploitation roughly one day after Adobe's patch release, while CVE-2026-5430 had a 133-day vendor-remediation-to-observed-exploitation interval.

Oct 1, 2026