The Maivia Gazette

Verified AI news, every morning

Security

GitLab patches a critical AI Gateway flaw that lets Duo agent users escape a sandbox and run commands

CVE-2026-90970 affects self-hosted AI Gateway instances. Customers on GitLab's hosted gateway are already protected.

An overhead view of a backyard sandbox with a toy crane lifting itself over the wooden border onto the grass.
AI-generated illustration, not event photography. The motion is AI-generated from the still.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.

GitLab has told customers to patch a critical vulnerability right away in its AI Gateway, the service that provides AI-native GitLab Duo features. The flaw, tracked as CVE-2026-90970, comes from an improper neutralization weakness. In its Friday advisory, GitLab said an authenticated user with Duo Agent Platform access could, under certain conditions, "escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway." BleepingComputer reports that an attacker would need only basic privileges plus access to the agent platform. The Hacker News puts the flaw's severity score at 9.9. GitLab runs its own cloud-hosted AI Gateway for GitLab.com, GitLab Self-Managed and GitLab Dedicated, and says customers using it are already protected and do not need to do anything. Organizations that deploy their own gateway through GitLab Duo Self-Hosted are exposed until they upgrade to version 19.2.4, 19.3.2 or 19.4.1. The bug shows how components that turn agent configurations into prompts can become a path to code execution on the servers that host them. That matters especially to organizations that self-host AI tooling to keep code and data in-house.

Sources

  1. BleepingComputerGitLab warns of critical RCE vulnerability in AI Gateway servicePublished · fetched
  2. Security AffairsCVE-2026-90970: Critical GitLab AI Gateway Flaw FixedPublished · fetched
  3. The Hacker NewsGitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted ServersPublished · fetched

Also in this edition