Executive Summary
On October 2, 2026, GitLab disclosed and patched a critical vulnerability (CVE-2026-90970, CVSS 9.9) in its AI Gateway component, specifically affecting self-hosted deployments supporting GitLab Duo AI features. This flaw allows authenticated users with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway host. The vulnerability is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine). While exploitation requires authentication, only low privileges are needed, and the risk of host compromise and lateral movement is severe. There is currently no evidence of exploitation in the wild or public proof-of-concept code. Immediate patching is strongly recommended.
Technical Information
CVE-2026-90970 is a critical template engine injection vulnerability in the GitLab AI Gateway (self-hosted). The vulnerability is rooted in the prompt template processing of custom flows within the Duo Agent Platform. Custom flows are YAML-defined, AI-powered workflows that automate multi-step tasks. The system uses Jinja2-style templating ({{ variable }}) to insert user-controlled data into prompts. Due to insufficient sandboxing, a crafted flow configuration can escape the template sandbox, leading to arbitrary command execution on the AI Gateway host. This is a template injection vulnerability, not a prompt injection; the attack occurs before the LLM is invoked, at the template engine layer.
The vulnerability is classified as CWE-1336 (Improper Neutralization of Special Elements Used in a Template Engine) and has a CVSS v3.1 score of 9.9 (Critical), with the following vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The attack vector is network-based, requires low privileges (an authenticated Duo Agent Platform user), and does not require user interaction. The scope is changed, meaning the attack crosses a security boundary, and the impact is arbitrary command execution on the AI Gateway host.
The exploitation path involves an attacker obtaining valid credentials for the Duo Agent Platform, creating or modifying a custom flow with a malicious prompt template, and having the flow processed by the AI Gateway, which escapes the template sandbox and executes arbitrary commands on the host. No public proof-of-concept or exploitation in the wild has been reported as of October 3, 2026.
Detection of exploitation may involve monitoring for unusual creation or modification of custom flows by unexpected or dormant accounts, the AI Gateway process spawning unexpected child processes (such as shells or binaries not typical for the service), unexpected file writes or access to sensitive environment files (such as JWT signing keys), outbound network connections from the AI Gateway to unfamiliar destinations, and attempts to enumerate credentials or lateral movement from the AI Gateway host. No specific YARA, Sigma, Suricata, or Nuclei rules are available as of this writing, so behavioral monitoring is recommended.
For investigation, audit logs should be reviewed for recent custom flow changes and associated user accounts, process monitoring should be conducted for anomalous processes spawned by the AI Gateway, network monitoring should be performed to identify unusual outbound connections, and file access should be checked for access to sensitive files or directories by the AI Gateway process.
Exploitation in the Wild
As of October 3, 2026, there is no evidence of exploitation in the wild for CVE-2026-90970. No public proof-of-concept code has been released, and no APT group or criminal campaign attribution has been found in open-source, MITRE, or vendor advisories. The CISA Known Exploited Vulnerabilities (KEV) catalog does not list this CVE, and therefore CISA does not confirm active exploitation.
APT Groups using this vulnerability
No evidence of APT group targeting, sector, or country-specific campaigns has been reported as of October 3, 2026. All available open-source and vendor advisories confirm no attribution or targeting information for CVE-2026-90970.
Affected Product Versions
The following versions of the GitLab AI Gateway are affected:
All versions from 18.1.6 up to (but not including) 19.2.4, all versions of 19.3 up to (but not including) 19.3.2, and all versions of 19.4 up to (but not including) 19.4.1. The first fixed versions are 19.2.4, 19.3.2, and 19.4.1 respectively. GitLab.com, GitLab Dedicated, and self-managed instances using GitLab-hosted gateways are not affected.
Workaround and Mitigation
Immediate upgrade to one of the following fixed versions is strongly recommended: 19.2.4, 19.3.2, or 19.4.1. Access to the Duo Agent Platform should be restricted to trusted users until patching is complete. Logs and configuration should be preserved before upgrading for potential forensic analysis. After patching, the running version of the AI Gateway should be verified (do not rely solely on the main GitLab application version). Permissions for creating or modifying custom flows should be reviewed and limited.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated before enforcement. No public indicators of compromise were available at the time of writing.
References
- GitLab AI Gateway Critical Patch Release
- The Hacker News: GitLab Patches Critical 9.9 AI Gateway Flaw
- Penligent.ai: CVE-2026-90970 Technical Analysis
- MITRE CWE-1336
- CISA KEV Catalog
- Canadian Centre for Cyber Security Advisory
Rescana is here for you
Rescana provides a comprehensive Third-Party Risk Management (TPRM) platform, empowering organizations to continuously monitor, assess, and manage cybersecurity risks across their vendor ecosystem. Our platform leverages advanced automation and threat intelligence to help you stay ahead of emerging threats and regulatory requirements. We are happy to answer any questions at info@rescana.com.



