AI-generated image of a cybersecurity operations centre with critical alerts for a NextNews GitLab AI Gateway vulnerability article Security

GitLab Warns of Critical 9.9-Rated AI Gateway Flaw — Users Urged to Patch Now

Share:

AI-generated image created for NextNews.

Security | 4 October 2026

GitLab is urging customers running its Self-Hosted AI Gateway to update immediately after fixing a critical vulnerability rated CVSS 9.9.

The flaw, tracked as CVE-2026-90970, affects certain self-hosted GitLab AI Gateway versions and could, under specific conditions, allow an authenticated user with Duo Agent Platform access to escape the prompt-template sandbox through a specially crafted flow configuration.

What the vulnerability could allow

GitLab says successful exploitation could lead to arbitrary command execution on the AI Gateway. Because the issue crosses a security boundary and could affect confidentiality, integrity and availability, GitLab assigned it a critical 9.9 score under CVSS 3.1.

The vulnerability is described as an improper neutralisation issue in custom flow prompt templates.

Which versions are affected?

According to GitLab, affected AI Gateway versions include releases from 18.1.6 before 19.2.4, the 19.3 branch before 19.3.2, and the 19.4 branch before 19.4.1.

The patched releases are:

  • 19.2.4
  • 19.3.2
  • 19.4.1

GitLab says administrators with affected self-hosted AI Gateway installations should move to one of the fixed versions as soon as possible.

Not every GitLab customer needs to act

The advisory does not mean every GitLab deployment is vulnerable. GitLab says a fix has already been deployed to its hosted AI Gateways.

Customers using GitLab.com, GitLab Dedicated, or Self-Managed GitLab instances that connect to a GitLab-hosted AI Gateway are already protected and do not need to take action for this issue.

Why AI infrastructure is becoming a security target

As software platforms add agentic AI capabilities, prompt templates, tool execution and workflow engines can become part of the security boundary. A flaw that lets a user escape an AI workflow sandbox can have consequences similar to more traditional application sandbox escapes.

That makes patching AI infrastructure just as important as updating operating systems, web applications and network services.

Source: GitLab critical patch advisory.

NextNews strives for accurate news, but readers should use this information with care. Details, availability and external links can change, and technical issues may occur. See our full disclaimer for details.

Disclaimer


NextNews strives for accurate news, but use it with caution—content changes often, external links may be iffy, and technical glitches happen. See the full disclaimer for details.

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.