GitLab Urges Immediate Patch for Critical AI Gateway Vulnerability (CVE-2026-90970)
GitLab has issued an urgent security advisory warning customers to patch a critical vulnerability in its AI Gateway service, which could allow attackers to execute arbitrary commands on unpatched instances. The flaw, tracked as CVE-2026-90970, affects self-hosted AI Gateway deployments on GitLab Self-Managed and stems from an improper neutralization weakness in the prompt template sandbox.
An authenticated user with Duo Agent Platform access could exploit the vulnerability by crafting a malicious flow configuration, bypassing security controls and gaining command execution on the AI Gateway. GitLab has released fixes in versions 19.2.4, 19.3.2, and 19.4.1, urging all self-hosted AI Gateway users to upgrade immediately. Customers using GitLab’s cloud-hosted AI Gateway are unaffected and require no action.
The company disclosed the vulnerability on Friday, following targeted outreach to self-hosted AI Gateway customers prior to public release. This follows another recent critical patch CVE-2026-85706, a maximum-severity path traversal flaw in GitLab Community and Enterprise Editions exploited in the wild to extract sensitive data. CISA added the latter to its Known Exploited Vulnerabilities Catalog, mandating federal agencies to remediate within three days under Binding Operational Directive 26-04.
GitLab’s platform, used by over 30 million users and 50% of Fortune 100 companies, has faced repeated exploitation, including attacks by ransomware groups. Since 2021, CISA has flagged five GitLab vulnerabilities actively abused in the wild.
GitLab cybersecurity rating report: https://www.rankiteo.com/company/gitlab-com
"id": "GIT1790965437",
"linkid": "gitlab-com",
"type": "Vulnerability",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Self-hosted AI Gateway users',
'industry': 'Software Development / DevOps',
'name': 'GitLab',
'size': '30 million users, 50% of Fortune 100 '
'companies',
'type': 'Company'}],
'attack_vector': 'Malicious flow configuration',
'customer_advisories': 'Urgent security advisory issued to patch '
'CVE-2026-90970',
'date_publicly_disclosed': 'Friday',
'description': 'GitLab has issued an urgent security advisory warning '
'customers to patch a critical vulnerability in its AI Gateway '
'service, which could allow attackers to execute arbitrary '
'commands on unpatched instances. The flaw, tracked as '
'CVE-2026-90970, affects self-hosted AI Gateway deployments on '
'GitLab Self-Managed and stems from an improper neutralization '
'weakness in the prompt template sandbox. An authenticated '
'user with Duo Agent Platform access could exploit the '
'vulnerability by crafting a malicious flow configuration, '
'bypassing security controls and gaining command execution on '
'the AI Gateway.',
'impact': {'operational_impact': 'Arbitrary command execution on unpatched '
'instances',
'systems_affected': 'GitLab Self-Managed AI Gateway deployments'},
'post_incident_analysis': {'corrective_actions': 'Patches released to fix the '
'vulnerability',
'root_causes': 'Improper neutralization weakness '
'in the prompt template sandbox'},
'recommendations': 'Upgrade to patched versions (19.2.4, 19.3.2, or 19.4.1) '
'immediately; monitor for exploitation attempts',
'references': [{'source': 'GitLab Security Advisory'},
{'source': 'CISA Known Exploited Vulnerabilities Catalog'}],
'regulatory_compliance': {'regulatory_notifications': 'CISA added '
'CVE-2026-85706 to '
'Known Exploited '
'Vulnerabilities '
'Catalog (Binding '
'Operational Directive '
'26-04)'},
'response': {'communication_strategy': 'Urgent security advisory issued; '
'targeted outreach to self-hosted AI '
'Gateway customers prior to public '
'release',
'containment_measures': 'Patches released in versions 19.2.4, '
'19.3.2, and 19.4.1',
'remediation_measures': 'Upgrade to patched versions (19.2.4, '
'19.3.2, or 19.4.1)'},
'stakeholder_advisories': 'Targeted outreach to self-hosted AI Gateway '
'customers prior to public release',
'title': 'GitLab Urges Immediate Patch for Critical AI Gateway Vulnerability '
'(CVE-2026-90970)',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-90970'}