CVE-2026-90970

LOWCVSS 9.9 · CRITICAL

Signal is active with 16 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1336

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 37 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 21 mentions (2026-10-02); latest day: 16
  • 37 total mentions across 2 days

Deep dive

Activity timeline37 mentions / 2d
05111621Mentions · 2026-10-02: 21Mentions · 2026-10-03: 1610-0210-03
Referenced assets25 URLs
By indicator
Full discourse20 posts
  • Dark Web Intelligence@DailyDarkWeb

    🚨 GITLAB CRITICAL — SELF-HOSTED AI GATEWAY RCE (CVE-2026-90970, CVSS 9.9) GitLab released Critical AI Gateway patch versions 19.2.4, 19.3.2, and 19.4.1 for a Critical security fix affecting GitLab Self-Hosted AI Gateway. • CVE-2026-90970 — Improper neutralization in custom flow prompt templates • Impact: authenticated Duo Agent Platform user can escape the prompt-template sandbox and run arbitrary commands on the AI Gateway • CVSS 9.9 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) • Impacted: AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 • http://GitLab.com, Dedicated, and Self-Managed using a GitLab-hosted AI Gateway are already protected — no action • Self-Hosted AI Gateway customers: upgrade immediately to 19.2.4 / 19.3.2 / 19.4.1 ⚠️ Analyst Note: Official GitLab Critical patch for Self-Hosted AI Gateway only — not a dark-web leak claim and not in CISA KEV as of this check. Requires an authenticated user with Duo Agent Platform access; not unauthenticated RCE. No in-the-wild exploitation claimed in the vendor notes reviewed here. Credit: invisiblemeerkat (responsible disclosure). Distinct from the Sep 23 GitLab CE/EE Critical regex RCE patch already covered on @DailyDarkWeb. Primary: https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/ #DDW #DarkWeb #GitLab #CVE202690970 #RCE #AIGateway #ThreatIntelligence #CyberSecurity

    0011065.1K
    206.1K followersView on X
  • elhacker.NET@elhackernet

    GitLab corrige vulnerabilidad crítica en AI Gateway 9.9 que permitía ejecución de comandos en servidores locales GitLab corrigió una vulnerabilidad crítica (CVE-2026-90970) en su AI Gateway que permitía a usuarios autenticados ejecutar comandos https://blog.elhacker.net/2026/10/gitlab-corrige-vulnerabilidad-critica.html

    010523.4K
    142.3K followersView on X
  • ExploitGrid@exploitgrid

    CVE-2026-90970 affects GitLab AI Gateway with a CVSS 9.9 severity. A logged-in Duo Agent user can escape the prompt template sandbox and execute commands on the self-hosted gateway. Update to 19.2.4, 19.3.2, or 19.4.1.

    11040164
    341 followersView on X
  • Slade 🛡️ LLM Hacker@llm_redteam

    CVE-2026-90970. CVSS 9.9. GitLab AI Gateway, fixed in 19.2.4 / 19.3.2 / 19.4.1. Any user with Duo Agent Platform access could craft a custom flow config that escapes the prompt template sandbox and runs arbitrary commands on the gateway. What makes this worth flagging: it's the same bug class as CVE-2026-1868, patched in February. Same component (Duo Workflow template engine), same CWE-1336 (template injection), same 9.9 score, same reporter base on HackerOne (invisiblemeerkat on this one). GitLab's advisory for 90970 doesn't even cross-reference the February CVE. That's two sandbox escapes in the same templating layer in eight months. A prompt template that renders user-controlled "flow configuration" into something executed server-side is not a one-off coding mistake, it's a design pattern that keeps producing RCE. [!] Affected: self-hosted AI Gateway, 18.1.6 through 19.1 (no fix exists below 19.2.4, so every release in that range is exposed with no workaround listed). [!] Not affected: http://GitLab.com, GitLab Dedicated, GitLab-hosted gateways. [!] Why the gateway matters: it holds JWT signing keys and brokers calls to your model provider. A command-exec escape there isn't contained to "AI feature broke," it's a foothold with credentials to pivot into your GitLab instance and your model provider account. CISA's exploitation assessment is "none" as of Oct 2, no public PoC. But with two near-identical escapes in one template engine, I'd bet on a third before year end unless GitLab rewrites the sandboxing model instead of patching the symptom. If you run a self-hosted gateway: check your version against 18.1.6-19.1 and update now, don't wait for a PoC to confirm urgency. #GitLab #PromptInjection #AIsecurity

    20021137
    1.3K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    GitLab fixed CVE-2026-90970, a critical 9.9 AI Gateway flaw in self-hosted servers that could let logged-in Duo Agent Platform users run commands. Patched in 19.2.4, 19.3.2, and 19.4.1. #GitLab #CVE202690970 #DuoAgentPlatform https://www.hendryadrian.com/gitlab-patches-critical-9-9-ai-gateway-flaw-allowing-command-execution-on-self-hosted-servers/

    10021236
    4.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews

    GitLab disclosed CVE-2026-90970, a critical AI Gateway RCE that can let authenticated users with basic privileges escape the sandbox and run arbitrary commands on self-hosted instances. #GitLab #CVE202690970 #AIGateway https://www.hendryadrian.com/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/

    10020213
    4.9K followersView on X
  • VulnTracker@vuln_tracker

    CVE-2026-90970: GitLab's AI Gateway, CVSS 9.9. A Duo Agent Platform sandbox escape leads to command execution, only self-hosted gateways need to act. Details: https://vulntracker.io/cves/CVE-2026-90970 #GitLab #AI #CVE #InfoSec https://t.co/yrRU4C3ltl

    1001038
    792 followersView on X
  • Daily CyberSecurity@Daily_CyberSec

    GitLab AI Gateway vulnerability CVE-2026-90970 (CVSS 9.9) lets Duo Agent Platform users run commands. Upgrade self-hosted gateways now. #GitLab #AIGateway #GitLabDuo #CVE202690970 #RCE #DevSecOps #Vulnerability https://securityonline.info/gitlab-ai-gateway-vulnerability/

    00020339
    13.0K followersView on X
  • skinnyguinea@_skinnyguinea

    GitLab just dropped a critical patch for Self-Hosted AI Gateway (CVE-2026-90970): authenticated Duo Agent Platform users can escape the prompt sandbox and run arbitrary commands on the gateway. Cloud/GitLab-hosted AI Gateway already covered. Self-hosted → jump to 19.2.4 / 19.3.2 / 19.4.1 now. https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/

    2000031
    110 followersView on X
  • Pierluigi Paganini - Security Affairs@securityaffairs

    CVE-2026-90970: Critical #GitLab AI Gateway Flaw Fixed https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html #securityaffairs #hacking

    00010149
    37.7K followersView on X
  • ابو سعود 💻@AbuSaud_Cyber

    🚨 عاجل: ثغرة خطيرة في GitLab AI Gateway تسمح بتنفيذ أوامر عن بعد GitLab نزلت تحديثات أمنية عاجلة لثغرة في الـ AI Gateway، الثغرة تسمح لمهاجم مسجل دخول إنه ينفذ أوامر عن بعد. الثغرة مسجلة باسم CVE-2026-90970 وتقييمها CVSS 9.9، يعني من أشد الثغرات، وتأثر على النسخ المستضافة ذاتيًا الي تدعم ميزات GitLab Duo. الشركة أصدرت إصدارات AI Gateway 19.2.4 و 19.3.2 و 19.4.1 لحل المشكلة. GitLab تشدد على العملاء الي عندهم Gateway مستضاف ذاتيًا إنهم يحدّثون فورًا، وكانوا تواصلوا معهم قبل ما ينشرون التنبيه الأمني عشان يعطونهم إرشادات مبدئية عن التحديثات المطلوبة.

    00010278
    1.6K followersView on X
  • اخبار داغ امنیت شبکه - تاکیان@Takianco

    🔴 گیت‌لب آسیب‌پذیری بحرانی CVE-2026-90970 (امتیاز ۹.۹) در سرویس AI Gateway خود را وصله کرده است؛ #CyberSecurity #GitLab #Vulnerability #AIGateway #AISecurity https://www.takian.ir/news/new-%DA%AF%DB%8C%D8%AA%E2%80%8C%D9%84%D8%A8-%DB%8C%DA%A9-%D9%86%D9%82%D8%B5-%D8%A8%D8%AD%D8%B1%D8%A7%D9%86%DB%8C-%D8%A8%D8%A7-%D8%A7%D9%85%D8%AA%DB%8C%D8%A7%D8%B2-%DB%B9-%DB%B9-%D8%AF%D8%B1-ai-gateway-%D8%B1%D8%A7-%D9%88%D8%B5%D9%84%D9%87-%DA%A9%D8%B1%D8%AF%D8%9B-%D8%B1%D8%A7%D9%87%DB%8C-%D8%A8%D9%87-%D8%B3%D9%85%D8%AA-%D8%A7%D8%AC%D8%B1%D8%A7%DB%8C-%D8%AF%D8%B3%D8%AA%D9%88%D8%B1-%D8%B1%D9%88%DB%8C-%D8%B3%D8%B1%D9%88%D8%B1%D9%87%D8%A7%DB%8C-%D8%AE%D9%88%D8%AF%D9%85%DB%8C%D8%B2%D8%A8%D8%A7%D9%86%DB%8C%E2%80%8C%D8%B4%D8%AF%D9%87 https://t.co/zTK6lWoGwr

    0001061
    641 followersView on X
  • zoomeyebot@zoomeyebot

    🚨 GitLab AI Gateway CVE-2026-90970: Authenticated Duo Users Can Run Arbitrary Commands Critical Vulnerability Alert! GitLab AI Gateway is affected by CVE-2026-90970. 🔍 Identify Targets via ZoomEye: Search Dork: app="GitLab" Exposure: 1.3m instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHaXRMYWIi #Infosec #CyberSecurity #ZoomEye

    1000027
    24 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate

    🚨 Securing Self-Hosted #AI Infrastructure: Mitigating GitLab’s Critical RCE Vulnerability (#CVE-2026-90970) + Video -Prediction: 📈 1 Positive | 📉 1 Negative https://undercodetesting.com/securing-self-hosted-ai-infrastructure-mitigating-gitlabs-critical-rce-vulnerability-cve-2026-90970-video/ Educational Purposes!

    0100035
    751 followersView on X
  • Upwind Security MDR@UpwindMDR

    🚨Critical - GitLab AI Gateway Prompt Template Sandbox Escape RCE (CVE-2026-90970) GitLab AI Gateway allows an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway. Instances without Duo Agent Platform access are not impacted. 👉Affected: GitLab AI Gateway 18.1.6-19.2.3, 19.3.0-19.3.1, 19.4.0 | Upgrade to 19.2.4/19.3.2/19.4.1

    1000066
    308 followersView on X
  • Ricardo Albuquerque@ralbuque

    GitLab corrigiu a CVE-2026-90970 (CVSS 9.9) no AI Gateway self-hosted: usuário com acesso ao Duo Agent Platform escapa do sandbox de templates e executa comandos. Atualize para 19.2.4, 19.3.2 ou 19.4.1; o gateway tem imagem/Helm próprios. https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html

    00000108
    20.0K followersView on X
  • SoTutto.it@SoTutto_it

    GitLab corregge CVE-2026-90970 nell’AI Gateway self-hosted: rischio di esecuzione comandi e patch nelle versioni 19.2.4, 19.3.2 e 19.4.1. #internet #cybersecurity #sicurezza #software https://sotutto.it/gitlab-falla-critica-ai-gateway-cve-2026-90970/ https://t.co/tkXQqYykhu

    0000013
    7 followersView on X
  • ro0TCr4k@ro0TCr4k

    GitLab has patched a critical AI Gateway flaw allowing command execution on self-hosted servers. CVE-2026-90970 scores 9.9, emphasizing the need for proactive security. RootCrak's autonomous scanning identifies vulnerabilities like this to protect your systems. https://t.co/Y1to3aLvh3

    0000030
    507 followersView on X
  • Cybersecurity News DE@cybsecuritynews

    #schwachstellen GitLab AI Gateway: Kritisches Update gegen mögliche Befehlsausführung #cve202690970 #gitlab #gitlabaigateway #gitlabduoagentplatform https://cybersecurity-news.de/gitlab-ai-gateway-kritisches-update-cve-2026-90970

    0000011
    15 followersView on X
  • Cyb3rVolt3x@AndraxPentester

    Scope note for triage: CVE-2026-90970 only hits self-hosted AI Gateway — http://GitLab.com, Dedicated, and GitLab-hosted gateways are already patched. Root cause is CWE-1336 in the custom-flow prompt template: Duo Agent Platform access + crafted flow config escapes the template sandbox to RCE on the gateway (CVSS 9.9, scope changed). Patch to 19.2.4 / 19.3.2 / 19.4.1 and inventory who actually runs self-hosted-v*.*-ee images before paging the whole org. Same template-engine class as February's CVE-2026-1868.

    0000021
    45 followersView on X

Explore more