ConicPlex

Start Your Project

A laptop glowing with warm orange light next to a cracked glass enclosure leaking light, on a desk in a dim developer workspace at night

On this Page

GitLab Patches a Critical AI Gateway Flaw That Let Attackers Run Commands on Self-Hosted Servers (CVE-2026-90970)

GitLab patched a critical CVE-2026-90970 flaw in its self-hosted AI Gateway on October 2, 2026, after a sandbox escape let authenticated users run arbitrary commands on the server.

Sajil Memon

October 4, 2026

GitLab shipped a fix on October 2, 2026 for CVE-2026-90970, a critical flaw (CVSS 9.9) in the self-hosted AI Gateway that powers GitLab Duo’s Agent Platform. An authenticated user with access to the Duo Agent Platform could craft a custom flow configuration that escaped the prompt-template sandbox and ran arbitrary commands on the gateway server. The bug affects AI Gateway versions 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Patched versions are 19.2.4, 19.3.2, and 19.4.1, and GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances using GitLab-hosted gateways were already protected before the advisory went public.

How the sandbox escape actually works

GitLab’s own advisory tracks the issue under CWE-1336, improper neutralization of special elements in a template engine. Duo Agent Platform lets teams build custom flows that feed data into prompt templates before they reach a model. The AI Gateway was supposed to treat that template data as inert text. CVE-2026-90970 broke that boundary: a flow configuration built a certain way let the template engine execute as code instead of rendering as a string, and that code ran with the gateway’s own permissions.

That matters because command execution on the gateway isn’t limited to the AI workflow itself. Once an attacker can run arbitrary commands on the host, they can read other data the gateway process can reach, pivot to connected services, or use the box as a foothold deeper into self-hosted infrastructure.

Who needs to act on this

This only applies to self-hosted deployments running their own AI Gateway for Duo Agent Platform. If every user on the instance already needs an account to touch Duo Agent Platform, the bar for exploitation is authenticated access, not an open internet-facing hole, but GitLab is treating it as critical because the outcome is full command execution rather than something limited like a crash or an information leak. The researcher who reported it, credited on GitLab’s advisory as invisiblemeerkat via HackerOne, flagged it as a sandbox bypass rather than a logic bug in one specific flow, which is why it reaches every custom flow configuration rather than a narrow feature.

There’s no workaround for versions still on the vulnerable range. GitLab’s advisory doesn’t offer a config flag or access restriction that neutralizes it short of upgrading, and it doesn’t describe a reliable way to check logs for past exploitation attempts either.

What to do this week

  • Upgrade self-hosted AI Gateway installations to 19.2.4, 19.3.2, or 19.4.1 depending on your current branch.
  • Review who actually has Duo Agent Platform access and trim it down if it’s wider than it needs to be.
  • Audit any custom flow configurations your team has built, since the exploit path runs through flow definitions rather than default settings.
  • If you’re on GitLab.com or GitLab Dedicated using GitLab-hosted gateways, no action is needed here specifically, but it’s still worth confirming which gateway mode your instance actually runs.

This is the second sandbox-escape disclosure affecting AI coding tools in the last few weeks, following the VM-escape flaws in Docker Sandboxes and the Plugin4Shell bug affecting Claude Code, Codex, Copilot, and Gemini CLI. The pattern is consistent: the isolation layer around an AI agent is now as much a target as the model itself, and teams that treat it as a settings checkbox rather than infrastructure to maintain are the ones that get caught flat when a CVE like this lands. If your team is evaluating or has already deployed AI coding agents or AI Gateway infrastructure and isn’t sure how exposed a self-hosted setup actually is, that’s exactly the kind of gap an AI Development audit is built to catch before it becomes an incident.

Sources

Sajil Memon is a co-founder of ConicPlex and a Senior Full Stack Developer focused on backend work: Node.js, PHP, APIs, and the infrastructure decisions that determine whether a system holds up under real traffic. He’s spent years on the side of a project that doesn’t get demoed, the part that has to keep working after launch. He writes here about the technical tradeoffs in backend architecture, deployment, and data handling that only become obvious once something breaks in production.

Leave a Reply

Your email address will not be published. Required fields are marked *

Keep reading

Plugins

Flat illustration of a purple shopping bag with a reserved tag and a clock, representing a WooCommerce pre-order plugin

Best WooCommerce Pre-Order Plugins: 3 Real Options Compared

Three real WooCommerce pre-order plugins compared: Pre-Orders for WooCommerce, YITH Pre-Order, and PRENA, with real prices, requirements, and setup steps…

Sajil Memon

October 5, 2026

Software

Laptop showing a blue dashboard interface on a desk overlooking a marina with yachts, representing real-time inventory sync for a WordPress fleet management plugin

WordPress Inventory Sync: Why Fleet and Rental Businesses Need More Than a Booking Plugin

A standard WordPress booking plugin assumes manual data entry. Fleet and rental businesses with large, API-driven inventories need real-time sync…

Aftab Memon

October 4, 2026

News & Updates

A laptop glowing with WordPress blue light on a dark desk at night, surrounded by several identical old brass keys half hidden under a notebook, symbolizing a backdoor that hides duplicate copies of itself.

WordPress Backdoor SC Survives Cleanup by Hiding in Files, Database, and Memory

Sucuri documented a self-healing WordPress backdoor called SC that rebuilds itself from eight hiding spots, including shared memory, after a…

Aftab Memon

October 3, 2026

WhatsApp
Husen Memon
Husen Memon
Typically replies instant