GitLab Warns of Critical AI Gateway RCE Flaw, Urges Immediate Patching
GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970, which affects Self-Hosted AI Gateway users.
GitLab warned customers to immediately patch a critical vulnerability in its AI Gateway service, tracked as CVE-2026-90970, according to BleepingComputer. The company released versions 19.2.4, 19.3.2, and 19.4.1 to address the flaw for Self-Hosted AI Gateway users.
The vulnerability could let an authenticated user with Duo Agent Platform access escape the prompt template sandbox and execute arbitrary commands, making it a remote code execution risk.
Customers using a GitLab-hosted AI Gateway are already protected and do not need to take action, the company said. GitLab also conducted targeted outreach to Self-Hosted AI Gateway customers before disclosing the flaw.
GitLab's DevSecOps platform has over 30 million registered users and is used by over 50% of Fortune 100 companies, underscoring the potential reach of a flaw in its tooling. In October 2025, GitLab patched a maximum severity path traversal vulnerability, CVE-2026-85706, in GitLab Community Edition and Enterprise Edition.
One day later, CISA added CVE-2026-85706 to its list of actively exploited flaws and gave federal agencies three days to secure their systems. Since November 2021, CISA has tagged five GitLab vulnerabilities abused in the wild, including one exploited by ransomware gangs.
Quick answers
What is CVE-2026-90970?
CVE-2026-90970 is a critical vulnerability in GitLab's AI Gateway that could allow an authenticated user with Duo Agent Platform access to escape the prompt template sandbox and execute arbitrary commands.
Which GitLab versions fix CVE-2026-90970?
GitLab released versions 19.2.4, 19.3.2, and 19.4.1 to fix the vulnerability for Self-Hosted AI Gateway users.
Do GitLab-hosted AI Gateway users need to patch?
No. Customers using a GitLab-hosted AI Gateway are already protected and do not need to take action.