GitLab shipped a fix on October 2, 2026 for CVE-2026-90970, a critical flaw (CVSS 9.9) in the self-hosted AI Gateway that powers GitLab Duo’s Agent Platform. An authenticated user with access to the Duo Agent Platform could craft a custom flow configuration that escaped the prompt-template sandbox and ran arbitrary commands on the gateway server. The bug affects AI Gateway versions 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Patched versions are 19.2.4, 19.3.2, and 19.4.1, and GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances using GitLab-hosted gateways were already protected before the advisory went public.
How the sandbox escape actually works
GitLab’s own advisory tracks the issue under CWE-1336, improper neutralization of special elements in a template engine. Duo Agent Platform lets teams build custom flows that feed data into prompt templates before they reach a model. The AI Gateway was supposed to treat that template data as inert text. CVE-2026-90970 broke that boundary: a flow configuration built a certain way let the template engine execute as code instead of rendering as a string, and that code ran with the gateway’s own permissions.
That matters because command execution on the gateway isn’t limited to the AI workflow itself. Once an attacker can run arbitrary commands on the host, they can read other data the gateway process can reach, pivot to connected services, or use the box as a foothold deeper into self-hosted infrastructure.
Who needs to act on this
This only applies to self-hosted deployments running their own AI Gateway for Duo Agent Platform. If every user on the instance already needs an account to touch Duo Agent Platform, the bar for exploitation is authenticated access, not an open internet-facing hole, but GitLab is treating it as critical because the outcome is full command execution rather than something limited like a crash or an information leak. The researcher who reported it, credited on GitLab’s advisory as invisiblemeerkat via HackerOne, flagged it as a sandbox bypass rather than a logic bug in one specific flow, which is why it reaches every custom flow configuration rather than a narrow feature.
There’s no workaround for versions still on the vulnerable range. GitLab’s advisory doesn’t offer a config flag or access restriction that neutralizes it short of upgrading, and it doesn’t describe a reliable way to check logs for past exploitation attempts either.
What to do this week
- Upgrade self-hosted AI Gateway installations to 19.2.4, 19.3.2, or 19.4.1 depending on your current branch.
- Review who actually has Duo Agent Platform access and trim it down if it’s wider than it needs to be.
- Audit any custom flow configurations your team has built, since the exploit path runs through flow definitions rather than default settings.
- If you’re on GitLab.com or GitLab Dedicated using GitLab-hosted gateways, no action is needed here specifically, but it’s still worth confirming which gateway mode your instance actually runs.
This is the second sandbox-escape disclosure affecting AI coding tools in the last few weeks, following the VM-escape flaws in Docker Sandboxes and the Plugin4Shell bug affecting Claude Code, Codex, Copilot, and Gemini CLI. The pattern is consistent: the isolation layer around an AI agent is now as much a target as the model itself, and teams that treat it as a settings checkbox rather than infrastructure to maintain are the ones that get caught flat when a CVE like this lands. If your team is evaluating or has already deployed AI coding agents or AI Gateway infrastructure and isn’t sure how exposed a self-hosted setup actually is, that’s exactly the kind of gap an AI Development audit is built to catch before it becomes an incident.



