GitLab Fixes Critical Vulnerability in Self-Hosted AI Gateway
GitLab has released fixes for the critical CVE-2026-90970 vulnerability in its AI Gateway service. It affects self-hosted deployments and could allow command execution after authentication.

GitLab AI Gateway fixes address the critical CVE-2026-90970 vulnerability, which has a CVSS score of 9.9. The flaw affects self-hosted deployments of the Self-Hosted AI Gateway service and, under certain conditions, could allow an authenticated user to execute arbitrary commands in the AI Gateway environment.
GitLab published the security advisory on October 2, 2026, and recommends that administrators of affected installations update immediately. Fixed versions 19.2.4, 19.3.2, and 19.4.1 are available.
GitLab AI Gateway fixes and affected version range
The vulnerability is tracked as CVE-2026-90970. According to GitLab, a logged-in user with access to the Duo Agent Platform could escape the prompt template sandbox. This can be done through modified flow configuration, after which an attacker could execute arbitrary commands on the AI Gateway.
The following Self-Hosted AI Gateway releases are affected:
- versions from 18.1.6 before version 19.2.4,
- the 19.3 branch before version 19.3.2,
- the 19.4 branch before version 19.4.1.
Administrators should deploy the appropriate fixed version for their branch: 19.2.4, 19.3.2, or 19.4.1. For self-hosted installations, GitLab recommends updating immediately.
This is not an unauthenticated attack
The published description and CVSS vector indicate that exploitation does not occur without login. An attacker must have authenticated access and permission to use the Duo Agent Platform. This does not change the severity of the impact in environments where multiple users have such access or where an attacker obtains valid credentials.
AI Gateway connects GitLab Duo with artificial intelligence models. If successfully exploited, the vulnerability would therefore give an attacker the ability to execute commands in the environment of the organization operating the service.
Who needs to update
The measure is intended for organizations operating their own Self-Hosted AI Gateway. GitLab said that its hosted AI Gateway services have already been fixed. According to the security advisory, customers of GitLab.com, GitLab Dedicated, and self-managed instances using GitLab-hosted AI Gateway do not need to take any action.
Before updating, organizations should verify that they are actually operating their own AI Gateway instance and determine which version they are using. They should then deploy the appropriate fixed build and confirm that the service runs version 19.2.4, 19.3.2, or 19.4.1 after the update.
Active exploitation has not been confirmed so far
In its published security advisory, GitLab does not report confirmed active exploitation of CVE-2026-90970 in the wild. The number of organizations with affected self-hosted deployments and the extent of completed updates are also unknown.
Administrators should monitor for any additions to the security advisory, particularly information about active exploitation, publicly available proof-of-concept code, indicators of compromise, or further recommended mitigations.
Sources
- GitLab Docs – GitLab’s primary advisory confirms the CVE, affected version range, CVSS 9.9, the authenticated-access requirement, available fixes, and the status of GitLab-hosted services.
- BleepingComputer – Independently confirms the publication date, the nature of the flaw, and the recommendation to update self-hosted deployments immediately.
Verified and updated: 10/03/2026 06:23



