Critical AI Gateway Flaw in GitLab Demands Immediate Patching
GitLab has issued an urgent warning to customers, advising them to immediately patch a critical vulnerability within its **AI Gateway** service. This flaw, tracked as **CVE-2026-90970**, could allow authenticated attackers to execute arbitrary commands on self-hosted instances, posing a significant risk to affected organizations.

**GitLab** is urging users of its self-hosted **AI Gateway** to apply urgent patches for a critical security vulnerability. The flaw, **CVE-2026-90970**, has the potential for arbitrary command execution.
## The AI Gateway Vulnerability Explained
The **AI Gateway** facilitates access to **GitLab Duo**'s AI-native features. While **GitLab** manages a cloud-based instance for **GitLab.com**, **GitLab Self-Managed**, and **GitLab Dedicated**, organizations can also deploy their own self-hosted instances via **GitLab Duo Self-Hosted**.
This critical vulnerability stems from an improper neutralization weakness. It allows attackers with basic privileges and **Duo Agent Platform** access to escape prompt template sandboxes through specially crafted flow configurations, leading to the execution of arbitrary commands on unpatched instances.
**GitLab** stated in its advisory: "**GitLab** has remediated an issue in the **GitLab AI Gateway** that, under certain conditions, could have allowed an authenticated user with **Duo Agent Platform** access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway."
## Required Actions for Self-Hosted Users
To address **CVE-2026-90970**, **GitLab** has released versions 19.2.4, 19.3.2, and 19.4.1. Customers utilizing **GitLab**-hosted **AI Gateway** instances are already protected and do not need to take any action. However, **GitLab Self-Managed** customers with self-hosted **AI Gateway** installations are strongly advised to update immediately.
"These versions contain a critical security fix for **GitLab Self-Hosted AI Gateway**, and we strongly recommend that all **GitLab Self-Managed** customers with **GitLab Self-Hosted AI Gateway** installations update to one of these versions immediately," the company emphasized.
**GitLab** confirmed that it conducted targeted outreach to self-hosted **AI Gateway** customers prior to the public disclosure, providing them with early guidance on the necessary upgrades.
## A Recent History of Critical Vulnerabilities
This isn't the first critical flaw **GitLab** has addressed recently. Last month, the company patched **CVE-2026-85706**, a maximum severity path traversal vulnerability affecting **GitLab Community Edition (CE)** and **Enterprise Edition (EE)**. This flaw allowed unauthenticated attackers to read sensitive data, including credentials and other secrets, from vulnerable servers.
One day after its disclosure, the **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** added **CVE-2026-85706** to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to patch their systems within three days.
Since November 2021, **CISA** has cataloged five **GitLab** vulnerabilities that have been actively exploited in the wild, some even by ransomware gangs. This highlights the importance of prompt patching for the **GitLab** platform, which boasts over 30 million registered users and is a critical component for over 50% of Fortune 100 companies, including **Nvidia**, **Lockheed Martin**, **T-Mobile**, **Goldman Sachs**, **Airbus**, and **UBS**.