GitLab Fixes Critical AI Gateway Flaw Allowing Code Execution
AI-generated image

GitLab Fixes Critical AI Gateway Flaw Allowing Code Execution

GitLab has fixed a critical flaw in its AI Gateway that could allow command execution on self-hosted servers. Users should update to versions 19.2.4, 19.3.2, or…

A critical security flaw in the GitLab AI Gateway has been patched, and organizations that run their own gateway need to apply the update immediately. GitLab disclosed the issue on October 2 and rated it critical, with a CVSS score of 9.9 out of 10, a standard severity scale where 10 is the highest. The weakness, tracked as CVE-2026-90970, could allow a logged-in user with access to GitLab's Duo Agent Platform, a tool for building AI-powered workflows, to run commands on the gateway under certain conditions.

The AI Gateway is the service that connects a GitLab instance to external AI models. Only organizations that host their own gateway need to take action. The flaw is fixed in gateway versions 19.2.4, 19.3.2, and 19.4.1. GitLab runs AI Gateways for its customers and has already fixed those hosted gateways. Customers on GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not need to do anything. Self-managed customers can choose to host their own gateway, an option GitLab offers for keeping AI request and response data inside the customer's own environment. GitLab strongly recommends that those customers update immediately, and it sent that guidance to customers with self-hosted gateways before it published the advisory.

According to the advisory, affected gateway versions include releases from 18.1.6 through the 19.2 line before 19.2.4, the 19.3 line before 19.3.2, and the 19.4 line before 19.4.1. No fixed version is listed below 19.2.4, which means every gateway release from 18.1.6 through the 19.1 line remains inside the affected range. GitLab's install guide tells administrators to use the gateway image that matches their GitLab minor version, but the advisory does not say whether a 19.2.4 gateway works with GitLab 19.1 or earlier, or whether fixes for the older lines are planned. As of October 2, GitLab's maintenance policy listed 19.4, 19.3, and 19.2 as the GitLab releases that get security fixes, and those are the same three lines that received the gateway fix.

To update a Docker deployment, which is a common way to run the gateway in a portable container, administrators need to stop and remove the running container, then pull and run the new image tag, for example self-hosted-v19.4.1-ee. Helm deployments, a package manager for Kubernetes, set the new tag in the chart's image setting. No workaround is listed for gateways that cannot be updated yet, and the advisory gives no way to check whether a gateway was attacked before it was updated.

The vulnerability is in the prompt template of a custom flow, according to the advisory's title. A custom flow is an AI-powered workflow that users create on the Duo Agent Platform to automate multi-step tasks. GitLab said a logged-in user with Duo Agent Platform access could escape the prompt template sandbox by sending a specially crafted flow configuration. That escape could lead to arbitrary command execution on the gateway, meaning a user could run commands on the underlying server. The conditions the attack needs are not described, and no user role is named beyond Duo Agent Platform access. A self-hosted gateway holds signing keys for JSON Web Tokens, or JWT, which are small digital credentials used to prove identity between services. GitLab's install guide says those keys must be treated as sensitive credentials. The gateway also connects to the GitLab instance and to the organization's AI model providers.

The advisory does not say whether the flaw has been used in attacks. The U.S. Cybersecurity and Infrastructure Security Agency, or CISA, added an assessment to the CVE record on October 2 that lists exploitation as none. CISA's other two values cover a public proof of concept and active exploitation. GitLab credited the HackerOne user invisiblemeerkat with reporting the flaw.

In February, GitLab fixed another gateway flaw, CVE-2026-1868, which was also rated 9.9. A logged-in user could reach that flaw through a crafted flow definition, and it could lead to denial of service or code execution on the gateway. Both flaws are template engine weaknesses of the same class, CWE-1336, a classification for weaknesses in template engines that can allow code injection and execution. The new advisory does not mention the February flaw.

For teams that run self-managed services like the GitLab AI Gateway, keeping the update process fast and controlled is important. AEU-I, AEU Group's security-first IT, infrastructure and consulting service, helps organizations review and maintain self-hosted components so that critical patches are applied consistently and credentials stay protected.

How to Protect Yourself

  1. If your organization runs its own GitLab AI Gateway, ask your IT team to check the version and update to 19.2.4, 19.3.2, or 19.4.1 right away.
  2. Until the update is applied, restrict who can use the Duo Agent Platform in your GitLab settings so only trusted accounts can create custom flows.
  3. Check your GitLab admin guide to confirm whether your gateway is self-hosted; if GitLab hosts it for you, no action is needed.
  4. After updating, restart the gateway according to GitLab's Docker or Helm instructions and verify the new version appears in the admin dashboard.
  5. Keep a list of people with Duo Agent Platform access and remove any accounts that no longer need it.

Vulnerabilities & Fixes

Terms Explained

  • AI Gateway A service that connects a GitLab installation to external AI models.
  • Duo Agent Platform GitLab's tool that lets users build AI-powered workflows to automate multi-step tasks.
  • Prompt template A prewritten pattern that tells an AI model how to respond; a custom flow uses one that can be misused.
  • CVSS score A standard 0 to 10 scale used to rate the severity of a security flaw.
  • CVE A unique identifier assigned to a publicly known security vulnerability.
  • JSON Web Token (JWT) A small digital credential used to prove identity between services; the gateway holds signing keys for these.
  • Docker A tool that packages software into a portable container so it can run consistently on different computers.
  • Helm chart A set of configuration files used to install and update software in a Kubernetes environment.

Related AEU services