Morning Edition · №
AI Security SAN FRANCISCO

Critical Flaw in GitLab's AI Gateway Could Have Let Users Hijack Self-Hosted Servers

A 9.9-severity bug in the prompt-template sandbox behind GitLab's Duo Agent Platform let logged-in users break out and run commands on the gateway, the company disclosed Friday.

Critical Flaw in GitLab's AI Gateway Could Have Let Users Hijack Self-Hosted Servers
— Photograph: FlyD / Unsplash
SHARE X f in ⧉

GitLab has patched a critical security flaw in the AI Gateway that powers its Duo Agent Platform, fixing a bug that let authenticated users break out of a prompt-template sandbox and run arbitrary commands on self-hosted servers. The company shipped fixes on Thursday and published an advisory Friday crediting a bug-bounty researcher for the find.

The vulnerability, tracked as CVE-2026-90970, carries a CVSS score of 9.9 out of 10, just shy of the maximum possible severity rating. It affects every release of GitLab's AI Gateway from version 18.1.6 through 19.4.0, according to GitLab's patch-release notes, which point self-managed customers to upgrade immediately to 19.2.4, 19.3.2 or 19.4.1. GitLab.com and GitLab Dedicated customers, whose instances the company manages directly, were already protected and did not need to take action.

The flaw lived in how the AI Gateway processes custom "flows" — automated, multi-step task sequences that users build on the Duo Agent Platform, GitLab's framework for letting AI agents carry out coding and DevOps tasks inside a repository. A specially crafted flow configuration could let a logged-in user escape the sandbox meant to contain prompt templates and reach the underlying gateway infrastructure, GitLab said, describing the bug as a way to "escape the prompt template sandbox via a specially crafted flow configuration."

A narrow door, but a serious one

Exploiting the bug required an attacker to already be an authenticated user with access to the Duo Agent Platform — not an anonymous, internet-facing attack. That narrows the pool of potential abusers but does little to blunt the severity rating, since GitLab's self-managed product is widely used inside banks, government agencies and large enterprises that run their own instances behind a login wall, meaning plenty of users could clear that bar. Once inside, GitLab's advisory indicates the flaw could lead to arbitrary command execution on the gateway itself, the kind of access that typically lets an intruder pivot deeper into connected systems.

The bug was reported through GitLab's HackerOne bug-bounty program by a researcher using the handle invisiblemeerkat, and it is not the first of its kind: GitLab patched a related template-engine weakness, CVE-2026-1868, in its AI Gateway back in February, suggesting the prompt-template sandbox has been a recurring soft spot as the company races to ship new agentic features, as The Hacker News first reported.

Part of a wider reckoning over agentic AI

The disclosure lands amid a broader industry scramble to lock down the permissions that coding and productivity agents now hold. As AI tools move from simply answering questions to autonomously executing commands, editing files and calling external systems, security researchers have repeatedly found that the sandboxes meant to contain them are easier to escape than vendors assume. GitLab's AI Gateway sits at exactly that pressure point: it is the piece of infrastructure that lets Duo's agents reach out to large language models and execute the steps those models recommend, which is precisely why a sandbox failure there is so consequential.

The U.S. Cybersecurity and Infrastructure Security Agency reviewed the flaw and, as of the advisory's publication Friday, assessed exploitation activity as "none," with no public proof-of-concept code or confirmed attacks in the wild. That assessment could change quickly now that technical details are public, which is why GitLab and independent researchers are urging self-managed customers not to wait.

For now, the fix is straightforward: self-hosted AI Gateway operators need to upgrade to one of the three patched releases, a process GitLab says is covered in its standard upgrade documentation. GitLab has not said whether it plans further changes to how custom flows are sandboxed, but the back-to-back nature of this year's two AI Gateway vulnerabilities suggests the company's security team will be revisiting that architecture before it ships its next round of agent features.

SHARE THIS ARTICLE X Facebook LinkedIn Copy link
Claire Fontaine · Technology & Regulation Correspondent

Reports on technology and its regulation for UBStandard, with a focus on Brussels, AI policy and Europe's digital economy.

[email protected]
Related coverage Front page →