GitLab patched a critical AI Gateway flaw letting Duo Agent Platform users run commands on the gateway

On October 2, 2026, GitLab published CVE-2026-90970 and released GitLab AI Gateway versions 19.2.4, 19.3.2 and 19.4.1 to fix it. The AI Gateway is the service that sits between GitLab and the language models behind its Duo features. Under certain conditions, an authenticated user with access to the Duo Agent Platform could submit a specially crafted custom flow configuration, escape the prompt template sandbox, and run arbitrary commands on the AI Gateway host.

GitLab rated the issue critical, CVSS 9.9, with a changed scope and high impact on confidentiality, integrity and availability. Affected versions are every AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. GitLab says it had already deployed a fix to the gateways it hosts, so GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted gateway were protected; the urgent action falls on self-managed customers running their own self-hosted AI Gateway, whom GitLab contacted before publishing. The finding came through HackerOne from a researcher using the handle invisiblemeerkat.

Why it matters: prompt templates are code in disguise. Letting users define custom agent flows means letting them feed text into a template engine on a server, and here that turned a low-privilege product feature into command execution on the component that holds model credentials and routes every Duo request. It is another case of the agent platform layer, rather than the model, carrying the most severe bug.

What it does not show: GitLab reported no exploitation, and the attack requires an authenticated account with Duo Agent Platform access on a vulnerable self-hosted gateway. GitLab’s advisory gives no technical detail beyond the description, so the exact template escape is not public.