As reported by BleepingComputer, GitLab has disclosed CVE-2026-90970, a critical remote code execution vulnerability in its AI Gateway service that enables authenticated users with basic privileges to escape the prompt template sandbox and execute arbitrary commands on the host. This is a significant disclosure for any organization running GitLab Duo Self-Hosted, and it highlights a recurring pattern we've been tracking: AI-adjacent infrastructure is becoming a prime attack surface, and the boundaries meant to contain AI workloads are proving fragile.
Vulnerability Summary
| Field | Detail |
|---|---|
| CVE | CVE-2026-90970 |
| Severity | Critical (CVSS not publicly listed at time of writing) |
| Affected Product | GitLab Self-Hosted AI Gateway (component of GitLab Duo Self-Hosted on GitLab Self-Managed) |
| Patched Versions | 19.2.4, 19.3.2, 19.4.1 |
| Cloud Instance | GitLab-hosted AI Gateway already patched — no customer action required |
| Active Exploitation | Not confirmed in the wild; GitLab conducted pre-disclosure outreach to affected customers |
| Prerequisites | Authenticated user with Duo Agent Platform access (low privilege) |
Why This Matters
The vulnerability class here — sandbox escape via prompt template manipulation — is not a traditional memory corruption or injection flaw. It's a logic vulnerability in how the AI Gateway processes flow configurations, allowing an authenticated, low-privilege user to break out of the intended execution boundary. This is the exact category of risk that security teams have been warning about as enterprises rush to integrate LLM tooling into developer workflows.
The exposure profile is also notable. GitLab's hosted cloud instance was patched transparently, meaning most customers are unaffected. But organizations that opted for self-hosted AI Gateway — typically larger enterprises with data residency, compliance, or sovereignty requirements — are now carrying unpatched critical RCE in their environments. These tend to be exactly the organizations whose GitLab instances hold source code, CI/CD secrets, deployment keys, and proprietary logic. An attacker who achieves code execution on the AI Gateway may be positioned to pivot toward the broader GitLab deployment and its connected CI/CD pipelines.
The irony is that the self-hosted deployment model — chosen for control and compliance — just introduced a critical RCE that the cloud model would have silently patched. Self-hosting AI infrastructure carries the same patching burden as any other service, but teams often treat AI components as managed even when they aren't.
Broader Context
This is GitLab's second high-profile disclosure in recent weeks. CVE-2026-85706, a maximum-severity path traversal in GitLab CE/EE, was patched last month and quickly added to CISA's Known Exploited Vulnerabilities catalog with a three-day remediation mandate under BOD 26-04. That CVE had a lower privilege bar — unauthenticated — but the pattern is clear: GitLab's sprawling codebase and rapid feature expansion are producing exploitable flaws at a pace that demands disciplined patch management from customers.
Shield53 Recommendations
Immediate Actions
Strategic Actions
- Reassess self-hosting decisions: For AI-specific services, weigh the patch latency and operational burden of self-hosting against the silent patching benefit of vendor-maned cloud. If you self-host for compliance, ensure your SLA for critical patches matches the risk.
- Add AI infrastructure to vulnerability scanning: Ensure your VM program covers AI Gateway, model servers, and LLM orchestration components — not just traditional application servers. These are now first-class attack targets.
- Review CISA KEV obligations: If CVE-2026-90970 is added to the KEV catalog, federal agencies and contractors will face a mandated remediation window. Monitor CISA advisories.
AI infrastructure is no longer a peripheral concern. It sits on the network, handles sensitive data, and now — as this CVE demonstrates — offers a viable path to code execution. Treat it with the same severity as any other critical service.