CVE-2026-90970: GitLab AI Gateway RCE Explained (2026)
The short answer
CVE-2026-90970 is a CVSS 9.9 template-injection flaw in GitLab’s self-hosted AI Gateway: any authenticated user with Duo Agent Platform access can craft a flow configuration that breaks out of the prompt-template sandbox and runs commands on the gateway host. Disclosed October 2, 2026; fixed in 19.2.4, 19.3.2 and 19.4.1. GitLab-hosted gateways are already patched. No exploitation in the wild had been reported as of October 3, 2026, but a compromised gateway exposes the JWT material that authenticates all downstream AI traffic, so self-hosters should treat it as patch-now. Facts verified October 4, 2026.
At a glance
| CVE | CVE-2026-90970 |
| Severity | CVSS 9.9 (Critical) |
| Weakness | CWE-1336 — template engine special-element injection |
| Component | GitLab AI Gateway (self-hosted), prompt templates behind Duo Agent Platform custom flows |
| Disclosed | October 2, 2026 |
| Reporter | invisiblemeerkat via HackerOne |
| Affected | 18.1.6 → 19.2.3; 19.3.0 → 19.3.1; 19.4.0 |
| Fixed | 19.2.4, 19.3.2, 19.4.1 |
| Not affected | GitLab.com, GitLab Dedicated, self-managed pointing at GitLab-hosted gateway |
| Prerequisites | Authenticated user with Duo Agent Platform access |
| Exploitation | None known (CISA, October 2, 2026); no public PoC |
What the bug is — and is not
The Duo Agent Platform lets users define custom flows: configurations that drive agents through prompt templates rendered by the AI Gateway. Those templates are rendered in a sandbox meant to stop template syntax from reaching the underlying engine. CVE-2026-90970 is a hole in that sandbox: a crafted flow configuration turns data the template was supposed to treat as text into instructions the template engine executes, and from there into arbitrary OS commands on the gateway process.
This is not prompt injection. Prompt injection manipulates what a language model says or does. This is a conventional server-side template injection (SSTI) that happens to live in AI infrastructure — the model is irrelevant to the exploit. The distinction matters for defenders: no amount of model-side guardrails, output filtering or “safety” tuning would have blocked it. Input validation on flow definitions and a correctly hardened template sandbox would.
Why it is worse than one bad code suggestion
Coverage from the security press converged on the same point: the AI Gateway is a trust anchor. It receives JWT signing material as environment variables to authenticate requests to downstream model providers and GitLab services. Command execution on the host means reading that environment, which means the ability to mint or replay tokens for the organisation’s entire AI request path. An attacker who starts as a developer with Duo access ends as the gateway.
Mitigation guidance split by deployment: in Docker, rebuild on a patched image and rotate any secrets the container could read; in Kubernetes, roll the deployment to a patched tag and rotate the mounted secrets. Rotation is the step teams skip. If the gateway was exploitable, assume its environment was readable.
A pattern, not a one-off
| CVE | Date | CVSS | Vector |
|---|---|---|---|
| CVE-2026-1868 | Feb 2026 | 9.9 | Crafted flow definition → template sandbox escape |
| CVE-2026-85706 | 2026 | — | Earlier AI Gateway flaw, unauthenticated |
| CVE-2026-90970 | Oct 2, 2026 | 9.9 | Crafted flow configuration → template sandbox escape |
Two CVSS 9.9 sandbox escapes in the same component in eight months, both through flow definitions, both CWE-1336, is a structural finding about how flow templates are handled rather than a single missed check. The October advisory does not reference the February one. If you run the gateway, the question for your vendor is what changed architecturally — not just which line was patched.
What to do
- Find out if you self-host the gateway. If your Duo traffic goes to GitLab-hosted AI Gateway, you are done.
- Upgrade to 19.2.4, 19.3.2 or 19.4.1 — whichever matches your line.
- Rotate JWT signing keys and any provider credentials the gateway container could read.
- Audit who has Duo Agent Platform access and review custom flow definitions created since your gateway was on an affected version.
- Watch for CISA KEV listing or a public PoC; both would change the urgency from “this week” to “today.”
Related: LiteLLM CVE-2026-42271 RCE explained, Cursor Duneslide RCE CVE-2026-50548, Cursor Origin vs GitHub vs GitLab agent code hosting.
Last verified: October 4, 2026, against GitLab’s advisory and CISA status as reported October 2–3, 2026.