thehackernews.com web signal

GitLab Patches CVSS 9.9 Sandbox Escape in Self-Hosted AI Gateway

TL;DR

  • GitLab disclosed CVE-2026-90970 on October 2, a CVSS 9.9 flaw letting authenticated Duo Agent Platform users escape the AI Gateway's prompt-template sandbox.
  • Fixed Gateway builds are 19.2.4, 19.3.2 and 19.4.1; affected versions span 18.1.6 through 19.4.0 on self-hosted deployments only.
  • A HackerOne researcher using the handle invisiblemeerkat reported the bug; CISA listed exploitation as none at disclosure.

GitLab disclosed a critical flaw in its self-hosted AI Gateway on October 2, assigning it a CVSS score of 9.9 out of 10. The bug, tracked as CVE-2026-90970, lives in the prompt template that powers custom flows inside Duo Agent Platform.

The Hacker News reported that any logged-in user with access to that platform could, in GitLab's own words, "escape the prompt template sandbox via a specially crafted flow configuration" and run arbitrary commands on the gateway itself.

Patched builds ship as 19.2.4, 19.3.2 and 19.4.1. Affected versions run from 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. GitLab.com, GitLab Dedicated and self-managed instances pointing at GitLab-hosted gateways are already patched; only organisations hosting their own AI Gateway need to act.

The bug was reported through HackerOne by a researcher using the handle invisiblemeerkat. CISA listed exploitation as "none" as of October 2, 2026.

It is the second critical gateway flaw this year. In February, GitLab patched CVE-2026-1868, another CVSS 9.9 issue in the same component, likewise exploitable through a crafted flow definition. Both are classified as template engine weaknesses under CWE-1336, though this week's advisory does not reference the earlier one. It is one of 198 cybersecurity items we have logged in the past 90 days on our AI cybersecurity tracker.