A important flaw in GitLab’s AI Gateway might let a logged-in person with Duo Agent Platform entry run instructions on the gateway underneath sure circumstances, GitLab stated in an advisory.
The gateway is the service that connects a GitLab occasion to AI fashions, and solely organizations that host their very own gateway must act. The flaw is mounted in gateway variations 19.2.4, 19.3.2, and 19.4.1.
The flaw is tracked as CVE-2026-90970. GitLab disclosed it on October 2 and rated it important, with a CVSS rating of 9.9 out of 10.
GitLab runs AI Gateways for its prospects and has already mounted them. Prospects on GitLab.com, GitLab Devoted, and self-managed cases that use a GitLab-hosted gateway don’t must act, the corporate stated.
Self-managed prospects can as an alternative host their very own gateway, an choice GitLab presents for preserving AI request and response information contained in the buyer’s personal atmosphere. GitLab strongly recommends that these prospects replace instantly. It despatched that steering to prospects with self-hosted gateways earlier than it revealed the advisory.
The advisory doesn’t say whether or not the flaw has been utilized in assaults. The U.S. Cybersecurity and Infrastructure Safety Company (CISA) added an evaluation to the CVE document on October 2 that lists exploitation as “none.” CISA’s different two values cowl a public proof of idea and lively exploitation.
Affected and Mounted Variations
The variations under are AI Gateway variations. The gateway is put in as its personal Docker picture or Helm chart and has its personal replace steps.
| Gateway model in use | First mounted model |
|---|---|
| 18.1.6 or later, earlier than 19.2.4 | 19.2.4 |
| 19.3, earlier than 19.3.2 | 19.3.2 |
| 19.4, earlier than 19.4.1 | 19.4.1 |
To replace a Docker deployment, cease and take away the operating container, then pull and run the brand new picture tag, for instance self-hosted-v19.4.1-ee. Helm deployments set the brand new tag within the chart’s picture setting.
No mounted model is listed under 19.2.4. That leaves each gateway launch from 18.1.6 via the 19.1 line contained in the affected vary.
GitLab’s set up information tells directors to make use of the gateway picture that matches their GitLab minor model. The advisory doesn’t say whether or not a 19.2.4 gateway works with GitLab 19.1 or earlier, or whether or not fixes for the older traces are deliberate.
As of October 2, GitLab’s upkeep coverage listed 19.4, 19.3, and 19.2 because the GitLab releases that get safety fixes. These are the identical three traces that received the gateway repair.
No workaround is listed for gateways that can not be up to date but. The advisory additionally offers no option to test whether or not a gateway was attacked earlier than it was up to date.
What Is Identified In regards to the Flaw
The flaw is within the immediate template of a customized movement, in keeping with the advisory’s title. A customized movement is an AI-powered workflow that customers create on the Duo Agent Platform to automate multi-step duties.
A logged-in person with Duo Agent Platform entry might have used the flaw to “escape the immediate template sandbox by way of a specifically crafted movement configuration,” GitLab stated. The escape might result in arbitrary command execution on the gateway.
The circumstances the assault wants should not described, and no person position is called past Duo Agent Platform entry.
A self-hosted gateway holds signing keys for JSON Net Tokens (JWT), which GitLab’s set up information says have to be handled as delicate credentials. It additionally connects to the GitLab occasion and to the group’s AI mannequin suppliers.
GitLab credited the HackerOne person invisiblemeerkat with reporting the flaw.
In February, GitLab mounted one other gateway flaw, CVE-2026-1868, which it additionally rated 9.9. A logged-in person might attain that flaw via a crafted movement definition, and it might result in denial of service or code execution on the gateway.
Each flaws are template engine weaknesses of the identical class, CWE-1336. The brand new advisory doesn’t point out the February flaw.










