GitLab AI Gateway Updates Fix Critical CVE-2026-90970
Quick Answer
The authority published CVE-2026-90970 for GitLab Self-Hosted AI Gateway. GitLab fixed a prompt-template sandbox escape that could let an authenticated Duo Agent Platform user use a crafted flow configuration to execute arbitrary commands on a self-hosted AI Gateway. Affected deployments should be matched to the authority's exact scope and moved to the supported fixed release.
Confirm Scope And Apply The Supported Fix
What to do now: Inventory GitLab Self-Hosted AI Gateway, match the exact affected release or feature, apply the authority-supported fixed build or service remediation, validate the dependent workflow, and preserve evidence.
Last verified: 2026-10-02 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | GitLab Self-Hosted AI Gateway |
|---|---|
| Advisory | CVE-2026-90970 |
| CVE | CVE-2026-90970 |
| Authoritative release date | 2026-10-02 (GitLab release-feed date; no time stated) |
| Authority revision date | Initial publication; no later material revision stated when verified |
| Affected versions | All GitLab AI Gateway versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. GitLab-hosted gateways are already fixed. |
| Fixed version | GitLab AI Gateway 19.2.4 / 19.3.2 / 19.4.1 |
| CVSS base score | 9.9 (official CVSS v3.1) |
| CVSS severity | Critical |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
GitLab fixed a prompt-template sandbox escape that could let an authenticated Duo Agent Platform user use a crafted flow configuration to execute arbitrary commands on a self-hosted AI Gateway.
What To Validate Now
- Inventory. Locate GitLab Self-Hosted AI Gateway deployments, versions, enabled features, exposure paths, owners, and dependent services.
- Establish applicability. Identify self-hosted AI Gateway deployments and match their exact version. GitLab.com, GitLab Dedicated, and Self-Managed instances using a GitLab-hosted AI Gateway are protected and require no action for this issue.
- Remediate. Upgrade each affected self-hosted AI Gateway to 19.2.4, 19.3.2, or 19.4.1 on its supported release line by following GitLab's installation and update guidance.
- Validate. Confirm the running AI Gateway version, validate GitLab Duo Agent Platform flows and integrations, review privileged process and flow-configuration telemetry for unexpected activity, rotate exposed secrets if investigation identifies compromise, and preserve evidence.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Back up configuration, test custom flows and model integrations, coordinate a maintenance window, preserve relevant logs before destructive action, and do not infer exploitation from the Critical rating.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

