GitLab Patches CVSS 9.9 Sandbox Escape in Self-Hosted AI Gateway
TL;DR
- HackerOne researcher invisiblemeerkat responsibly disclosed the flaw; CISA lists exploitation status as none and no public proof-of-concept has been released.
- The AI Gateway is a separately versioned component; upgrading core GitLab does not remediate CVE-2026-90970 and operators must update the Gateway image directly to 19.2.4, 19.3.2, or 19.4.1.
- The injection fires in the Jinja2 template engine before LLM invocation, making this a server-side code execution path rather than an AI prompt injection attack.
GitLab disclosed a critical flaw in its self-hosted AI Gateway on October 2, assigning it a CVSS score of 9.9 out of 10. The bug, tracked as CVE-2026-90970, lives in the prompt template that powers custom flows inside Duo Agent Platform.
The Hacker News reported that any logged-in user with access to that platform could, in GitLab's own words, "escape the prompt template sandbox via a specially crafted flow configuration" and run arbitrary commands on the gateway itself.
Patched builds ship as 19.2.4, 19.3.2 and 19.4.1. Affected versions run from 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. GitLab.com, GitLab Dedicated and self-managed instances pointing at GitLab-hosted gateways are already patched; only organisations hosting their own AI Gateway need to act.
The bug was reported through HackerOne by a researcher using the handle invisiblemeerkat. CISA listed exploitation as "none" as of October 2, 2026.
It is the second critical gateway flaw this year. In February, GitLab patched CVE-2026-1868, another CVSS 9.9 issue in the same component, likewise exploitable through a crafted flow definition. Both are classified as template engine weaknesses under CWE-1336, though this week's advisory does not reference the earlier one. It is one of 198 cybersecurity items we have logged in the past 90 days on our AI cybersecurity tracker.
What others are reporting
-
Security Affairs Read →
Names HackerOne researcher invisiblemeerkat as the responsible discloser; confirms no PoC published and no exploitation detected in the wild.
An authenticated user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution.
-
Cyberpress Read →
Stresses that the AI Gateway is a separate component and administrators must patch the Gateway image directly, not assume a core GitLab upgrade covers the fix.
A successful sandbox escape could result in arbitrary command execution on the AI Gateway host or container.
-
SQ Magazine Read →
Compares to prior CVE-2026-85706, which required no authentication on the same surface, framing stolen or insider credentials as the primary remaining attack vector for this follow-on flaw.
A specially crafted flow configuration could let a user escape the prompt template sandbox. That escape leads to command execution on the gateway itself.
-
Rescana Read →
Provides forensic investigation guidance and clarifies the flaw is template engine injection before LLM invocation, not prompt injection, with specific detection signals for JWT key file access.
Due to insufficient sandboxing, a crafted flow configuration can escape the template sandbox, leading to arbitrary command execution on the AI Gateway host.
-
Security Online Read →
Recommends narrowing Duo Agent Platform permissions as an interim mitigation while patches are staged across self-hosted fleets.
-
DEV Community Read →
Technical walkthrough documenting the full post-exploitation chain including JWT key theft, model provider credential access, and the need to rotate Gateway credentials after any compromise assessment.
A crafted Duo Agent Platform flow configuration escapes the prompt template sandbox, reaching JWT signing keys and model provider credentials held by the Gateway host.
Originally reported by thehackernews.com
Read the original article →Original headline: GitLab Patches Critical CVE-2026-90970 in Self-Hosted AI Gateway, CVSS 9.9 Lets Users Escape Prompt Sandbox