As reported by BleepingComputer, GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service that enables authenticated users with basic privileges to escape the prompt template sandbox and execute arbitrary commands on the host. This is a significant disclosure for any organization running GitLab Duo Self-Hosted, and it highlights a recurring pattern we've been tracking: AI-adjacent infrastructure is becoming a prime attack surface, and the boundaries meant to contain AI workloads are proving fragile.

Security Impact: As reported by BleepingComputer, GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service that enables authenticated users with basic privileges to escape the prompt template sandbox and execute arbitrary commands on the host.

Vulnerability Summary

FieldDetail
CVECVE-2026-90970
SeverityCritical (CVSS not publicly listed at time of writing)
Affected ProductGitLab Self-Hosted AI Gateway (component of GitLab Duo Self-Hosted on GitLab Self-Managed)
Patched Versions19.2.4, 19.3.2, 19.4.1
Cloud InstanceGitLab-hosted AI Gateway already patched — no customer action required
Active ExploitationNot confirmed in the wild; GitLab conducted pre-disclosure outreach to affected customers
PrerequisitesAuthenticated user with Duo Agent Platform access (low privilege)

Why This Matters

The vulnerability class here — sandbox escape via prompt template manipulation — is not a traditional memory corruption or injection flaw. It's a logic vulnerability in how the AI Gateway processes flow configurations, allowing an authenticated, low-privilege user to break out of the intended execution boundary. This is the exact category of risk that security teams have been warning about as enterprises rush to integrate LLM tooling into developer workflows.

The exposure profile is also notable. GitLab's hosted cloud instance was patched transparently, meaning most customers are unaffected. But organizations that opted for self-hosted AI Gateway — typically larger enterprises with data residency, compliance, or sovereignty requirements — are now carrying unpatched critical RCE in their environments. These tend to be exactly the organizations whose GitLab instances hold source code, CI/CD secrets, deployment keys, and proprietary logic. An attacker who achieves code execution on the AI Gateway may be positioned to pivot toward the broader GitLab deployment and its connected CI/CD pipelines.

The irony is that the self-hosted deployment model — chosen for control and compliance — just introduced a critical RCE that the cloud model would have silently patched. Self-hosting AI infrastructure carries the same patching burden as any other service, but teams often treat AI components as managed even when they aren't.

Broader Context

This is GitLab's second high-profile disclosure in recent weeks. CVE-2026-85706, a maximum-severity path traversal in GitLab CE/EE, was patched last month and quickly added to CISA's Known Exploited Vulnerabilities catalog with a three-day remediation mandate under BOD 26-04. That CVE had a lower privilege bar — unauthenticated — but the pattern is clear: GitLab's sprawling codebase and rapid feature expansion are producing exploitable flaws at a pace that demands disciplined patch management from customers.

Shield53 Recommendations

Immediate Actions

Broader Context
Identify exposed instances: Inventory all GitLab Self-Managed deployments and determine which are running GitLab Duo Self-Hosted with a local AI Gateway. Any version below 19.2.4, 19.3.2, or 19.4.1 (depending on your branch) is vulnerable.
Patch now: Upgrade the AI Gateway component to 19.4.1 (or the corresponding patched release for your branch: 19.2.4 or 19.3.2). Do not delay for change windows — this is critical RCE on AI infrastructure.
Restrict Duo Agent Platform access: Until patched, review who holds Duo Agent Platform access. The exploit requires authentication, so limiting that surface reduces interim risk. Revoke unused or stale access tokens.
Hunt for indicators of compromise: Review AI Gateway logs for anomalous flow configurations, unexpected process execution, or outbound connections from the gateway host. The sandbox escape implies the attacker may have executed system commands — look for shell invocation patterns in audit logs.
Segment the AI Gateway: Ensure the AI Gateway host is network-segmented from critical GitLab components, CI/CD runners, and secrets stores. A compromised gateway should not have a direct path to deployment infrastructure.

Strategic Actions

  • Reassess self-hosting decisions: For AI-specific services, weigh the patch latency and operational burden of self-hosting against the silent patching benefit of vendor-maned cloud. If you self-host for compliance, ensure your SLA for critical patches matches the risk.
  • Add AI infrastructure to vulnerability scanning: Ensure your VM program covers AI Gateway, model servers, and LLM orchestration components — not just traditional application servers. These are now first-class attack targets.
  • Review CISA KEV obligations: If CVE-2026-90970 is added to the KEV catalog, federal agencies and contractors will face a mandated remediation window. Monitor CISA advisories.

AI infrastructure is no longer a peripheral concern. It sits on the network, handles sensitive data, and now — as this CVE demonstrates — offers a viable path to code execution. Treat it with the same severity as any other critical service.