GBHackers

Critical GitLab AI Gateway Flaw Lets Attackers Execute Arbitrary Commands


GitLab has issued emergency security updates for a critical vulnerability in its Self-Hosted AI Gateway that could allow authenticated attackers to execute arbitrary commands on vulnerable AI Gateway deployments.

The flaw, tracked as CVE-2026-90970, carries a CVSS severity score of 9.9 out of 10. The company released GitLab AI Gateway versions 19.2.4, 19.3.2, and 19.4.1 to address the issue.

The vulnerability affects the AI Gateway component used to support GitLab Duo Self-Hosted capabilities, including AI-assisted development workflows deployed within customer-controlled environments.

Critical GitLab AI Gateway Flaw

GitLab said it has already reached out to potentially affected Self-Hosted AI Gateway customers before publicly publishing the security advisory. CVE-2026-90970 is described as an improper neutralization vulnerability in GitLab AI Gateway’s custom flow prompt template functionality.

Under certain conditions, an authenticated user with access to the Duo Agent Platform could create or submit a specially crafted flow configuration that escapes the intended prompt-template sandbox. Successful exploitation could lead to arbitrary command execution on the AI Gateway host or environment.

This creates a significant risk because command execution could enable an attacker to access sensitive development data, manipulate AI workflow configurations, steal service credentials, move laterally within connected infrastructure, or disrupt AI-enabled development operations.

The CVSS 3.1 vector for the issue is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. The score reflects that exploitation can occur remotely with low attack complexity and does not require user interaction, although the attacker must first have low-privileged authenticated access to the affected Duo Agent Platform functionality.

Affected GitLab AI Gateway Versions

The issue impacts GitLab AI Gateway installations beginning with version 18.1.6 and affects the following version ranges:

Affected release lineVulnerable versionsFixed version
GitLab AI Gateway 18.x through 19.218.1.6 through versions before 19.2.419.2.4
GitLab AI Gateway 19.319.3 through versions before 19.3.219.3.2
GitLab AI Gateway 19.419.4 through versions before 19.4.119.4.1

GitLab-hosted AI Gateway customers are not affected by this remediation requirement. The company confirmed that it has already deployed a fix for GitLab-hosted AI Gateway environments.

As a result, customers using GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances configured to use a GitLab-hosted AI Gateway are protected and do not need to take action.

Mitigation

Organizations running Self-Hosted AI Gateway should prioritize upgrading to version 19.2.4, 19.3.2, or 19.4.1 based on their supported release track.

Security teams should also review Duo Agent Platform access assignments, inspect custom flow configurations for unexpected or unauthorized changes, and monitor AI Gateway logs for suspicious command execution activity.

Because exploitation requires authenticated access, restricting Duo Agent Platform permissions and reviewing accounts with access to custom flow capabilities can reduce exposure while patching is underway. However, access controls should not replace installing the security update.

GitLab’s fix addresses a growing security concern around AI workflow platforms: prompt and template components must be strictly isolated from underlying execution environments.

Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC



Source link