GitLab patches a critical AI Gateway flaw that lets Duo agent users escape a sandbox and run commands
CVE-2026-90970 affects self-hosted AI Gateway instances. Customers on GitLab's hosted gateway are already protected.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
GitLab has told customers to patch a critical vulnerability right away in its AI Gateway, the service that provides AI-native GitLab Duo features. The flaw, tracked as CVE-2026-90970, comes from an improper neutralization weakness. In its Friday advisory, GitLab said an authenticated user with Duo Agent Platform access could, under certain conditions, "escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway." BleepingComputer reports that an attacker would need only basic privileges plus access to the agent platform. The Hacker News puts the flaw's severity score at 9.9. GitLab runs its own cloud-hosted AI Gateway for GitLab.com, GitLab Self-Managed and GitLab Dedicated, and says customers using it are already protected and do not need to do anything. Organizations that deploy their own gateway through GitLab Duo Self-Hosted are exposed until they upgrade to version 19.2.4, 19.3.2 or 19.4.1. The bug shows how components that turn agent configurations into prompts can become a path to code execution on the servers that host them. That matters especially to organizations that self-host AI tooling to keep code and data in-house.