GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)
GitLab AI Gateway critical RCE via prompt template sandbox (TL-2026-2846) is a critical-severity software vulnerability scored CVSS 9.9, first published 2026-10-02 and last reviewed 2026-10-03. It has no confirmed attribution, affects GitLab AI Gateway (Self-Managed Self-Hosted), references 1 CVE (CVE-2026-90970), maps to 6 MITRE ATT&CK techniques (T1059, T1068, T1078), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2846
- Threat ID
- TL-2026-2846
- Severity
- CRITICAL
- CVSS
- 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-10-02
- Last reviewed
- 2026-10-03
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, software-development, enterprise
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
- Updates
- 2026-10-03 · revalidated 1× · latest source
GitLab patched a critical (CVSS 9.9) flaw in the self-hosted AI Gateway that lets an authenticated user with Duo Agent Platform access escape the prompt template sandbox through a crafted flow configuration and run arbitrary commands on the gateway. Fixed in AI Gateway 19.2.4, 19.3.2 and 19.4.1; no active exploitation or public PoC has been reported.
How GitLab AI Gateway critical RCE via prompt template sandbox works
CVE-2026-90970 is an improper neutralization weakness (CWE-1336) in the custom flow prompt template handling of the GitLab AI Gateway, the service that brokers GitLab Duo / Duo Agent Platform requests to LLM back ends in Self-Managed Self-Hosted deployments. Per GitLab's advisory ("Improper Neutralization issue in custom flow prompt template impacts AI Gateway") and the NVD record, an authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
The CVSS 3.1 vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H (9.9). Network-reachable, low complexity, low privileges and no user interaction are required. Scope is changed, reflecting that code execution in the gateway crosses the sandbox boundary and impacts resources beyond the template engine. Affected versions are AI Gateway 18.1.6 through 19.2.3, 19.3.0 through 19.3.1 and 19.4.0. Fixed versions are 19.2.4, 19.3.2 and 19.4.1. GitLab-hosted environments (GitLab.com, Dedicated, and Self-Managed instances using the GitLab-hosted gateway) are already protected and need no action; only self-hosted AI Gateway installations must upgrade following the official Self-Hosted AI Gateway documentation. The issue was reported through HackerOne by researcher invisiblemeerkat. GitLab conducted targeted outreach to affected customers before disclosure, and BleepingComputer reports no active exploitation, no public PoC and no attribution.
This is the second critical template-sandbox class issue in the same component in 2026. CVE-2026-1868 (also CVSS 9.9, same vector, fixed February 6, 2026 in AI Gateway 18.6.2, 18.7.1 and 18.8.1; found internally by GitLab's Joern Schneeweisz) described insecure template expansion of user-supplied data via crafted Duo Agent Platform Flow definitions in the Duo Workflow Service, enabling denial of service or code execution on the gateway. GitLab also remediated separate AI Gateway flaws involving crafted inline flow configuration overriding the HTTP Host header to redirect model requests and expose cloud credentials. Because the AI Gateway typically holds LLM provider credentials and signing material, command execution on it should be treated as a pivot point into connected cloud and model-provider accounts.
Separate from this flaw, GitLab core had a different, unauthenticated issue in September 2026: CVE-2026-85706, a CVSS 10.0 path traversal / authentication bypass in the repository commits API of GitLab CE/EE, added to CISA KEV on 2026-09-11 with public PoCs within hours. BleepingComputer cites it for context; it is not the same vulnerability and CVE-2026-90970 itself has no reported exploitation. No IOCs have been published; defenders should rely on version inventory, review of Duo Agent Platform flow definitions, and process/egress telemetry on the gateway host.
MITRE ATT&CK techniques used in TL-2026-2846
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1078 Valid Accounts
Initial Access
T1078 Valid Accounts; T1190 Exploit Public-Facing Application
Credential Access
T1552 Unsecured Credentials; T1552.004 Unsecured Credentials: Private Keys
Affected products and versions in GitLab AI Gateway critical RCE via prompt template sandbox
- GitLab — AI Gateway (Self-Managed Self-Hosted)
Vulnerable versions: 18.1.6 through 19.2.3; 19.3.0 through 19.3.1; 19.4.0
Fixed in: 19.2.4; 19.3.2; 19.4.1
Remediation for GitLab AI Gateway critical RCE via prompt template sandbox
Patches
- GitLab AI Gateway 19.2.4
- GitLab AI Gateway 19.3.2
- GitLab AI Gateway 19.4.1
Immediate actions
- Upgrade self-hosted GitLab AI Gateway to 19.2.4, 19.3.2 or 19.4.1 (or later)
- Restrict Duo Agent Platform access to trusted users until patched
- Review custom flow configurations and prompt templates for unexpected template expressions
Workarounds
- No workaround published; GitLab-hosted AI Gateway (GitLab.com, Dedicated, GitLab-hosted gateway for Self-Managed) is already remediated
Longer-term hardening
- Run the AI Gateway with least privilege, in an isolated network segment with restricted egress
- Store LLM provider credentials in a secrets manager and rotate them if gateway compromise is suspected
- Monitor child-process creation and outbound connections from the AI Gateway service
CVEs associated with GitLab AI Gateway critical RCE via prompt template sandbox
CVE-2026-90970
Weaknesses (CWE) in GitLab AI Gateway critical RCE via prompt template sandbox
CWE-1336
Timeline of GitLab AI Gateway critical RCE via prompt template sandbox
- GitLab releases AI Gateway 18.6.2, 18.7.1 and 18.8.1 fixing CVE-2026-1868 (CVSS 9.9), insecure template expansion via crafted Duo Agent Platform Flow definitions, the same attack surface later hit by CVE-2026-90970. Found internally by Joern Schneeweisz.
- Canadian Centre for Cyber Security publishes advisory AV26-103 urging upgrade of Duo Self-Hosted AI Gateway for the earlier critical flaw.
- CVE-2026-19889 (CVSS 8.2 SSRF via crafted model metadata, AI Gateway 18.9.0-19.2.2, CWE-918) published, exposing Google Vertex AI or AWS Bedrock credentials.
- CVE-2026-75871 (CVSS 8.2 SSRF via crafted inline flow configuration in AI Gateway, CWE-918) published; a separate flaw in the same flow-handling attack surface.
- Unrelated GitLab core flaw CVE-2026-85706 (CVSS 10.0 unauthenticated path traversal, CE/EE) added to CISA KEV on disclosure day, with public PoCs within hours; cited by BleepingComputer as context for GitLab's exploitation history.
- GitLab releases critical core patch 19.4.1, 19.3.3, 19.2.7 for CE/EE (separate from the AI Gateway release).
- The Hacker News reports the flaw, noting the gateway holds JWT signing keys, that no fix is provided below 18.1.6, and that Docker and Helm deployments must be updated; no known exploitation or public PoC.
- BleepingComputer reports GitLab warning of the critical AI Gateway RCE; GitLab-hosted instances already protected, GitLab did targeted customer outreach, no active exploitation reported.
- CVE-2026-90970 published in NVD (CVSS 9.9, CWE-1336) with GitLab AI Gateway patch release 19.4.1 / 19.3.2 / 19.2.4; reporter credited as invisiblemeerkat via HackerOne.
Update history for TL-2026-2846
- 2026-10-03 — GitLab AI Gateway Critical Flaw (CVE-2026-90970) Allows Command Execution on Self-Hosted Servers: What changed No severity, exploitability or status change; the second-source report restates the same facts and adds context. New indicators (4) Docker/Helm deployment forms, JWT signing keys as an at-risk asset, and two related AI Gateway
Sources cited for GitLab AI Gateway critical RCE via prompt template sandbox
- GitLab warns of critical RCE vulnerability in AI Gateway service
- GitLab AI Gateway Patch Release 19.4.1 (CVE-2026-90970)
- NVD - CVE-2026-90970
- GitLab work item 628842 (CVE-2026-90970 issue)
- GitLab AI Gateway Critical Patch Release 18.6.2, 18.7.1, 18.8.1 (CVE-2026-1868)
- Canadian Centre for Cyber Security - GitLab security advisory AV26-103
- GitLab Critical Patch Release 19.4.1, 19.3.3, 19.2.7
- CISA: hackers now exploit max severity GitLab flaw in attacks (CVE-2026-85706, context)
- Wiz vulnerability database - CVE-2026-85706 (context)
- Rapid7 ETR - CVE-2026-85706 critical GitLab path traversal exploited in the wild (context)
More in vulnerability
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes (CVE-2026-63688, CVE-2026-63692, CVE-2026-67269, CVE-2026-54472, CVE-2026-61421, CVE-2026-67273)
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490 (local privilege escalation to root), chained in an agentic-AI attack on DIVD
- Sony PS5 'Relapse' Jailbreak Exploit Chains JSC Memory Corruption and Kernel UAF (aio_multi_wait) on Firmware 7.00-13.60
- Multiple Vulnerabilities in Microsoft Edge prior to 154.0.4258.53 (HK GovCERT A26-10-03)
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wild
Detection coverage for TL-2026-2846
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2846 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.