Description
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Published: 2026-10-02
Score: 9.9 Critical
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The GitLab AI Gateway component contains a flaw in its template engine that fails to properly neutralize special elements. An authenticated user with Duo Agent Platform access can craft a flow configuration that escapes the sandbox and causes the gateway to execute arbitrary commands. The weakness is a classic template injection issue (CWE‑1336), allowing an attacker to gain remote code execution capabilities on the underlying system that hosts the AI Gateway.

Affected Systems

Affected are all GitLab AI Gateway releases from 18.1.6 up to but excluding 19.2.4, from 19.3 before 19.3.2, and from 19.4 before 19.4.1. The vulnerability resides exclusively in the AI Gateway component and applies to installations that grant Duo Agent Platform users permission to modify flow configurations.

Risk and Exploitability

The CVSS base score of 9.9 indicates critical severity, and the exploitability is high because the attacker only needs authenticated Duo Agent Platform credentials, a common role in many organizations. The EPSS value is not available, and the vulnerability is not catalogued in CISA KEV. Thus, the risk is considerable, and organizations should act quickly to patch or otherwise mitigate the flaw.

Generated by OpenCVE AI on October 2, 2026 at 15:20 UTC.

Remediation

Vendor Solution

Upgrade to version 19.2.4, 19.3.2, 19.4.1 or above.


OpenCVE Recommended Actions

  • Apply the latest patch to GitLab AI Gateway (19.2.4, 19.3.2, 19.4.1 or newer).
  • Restrict Duo Agent Platform access to only trusted administrators and remove unnecessary permissions for users who do not need to configure flow templates.
  • Conduct a review of existing flow configurations and disable or sanitize any that contain unsanitized template syntax, and test sandbox isolation to confirm the vulnerability is mitigated.

Generated by OpenCVE AI on October 2, 2026 at 15:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 02 Oct 2026 14:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Title Improper Neutralization of Special Elements Used in a Template Engine in GitLab AI Gateway
First Time appeared Gitlab
Gitlab ai-gateway
Weaknesses CWE-1336
CPEs cpe:2.3:a:gitlab:ai-gateway:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab ai-gateway
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Gitlab Ai-gateway
cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-02T16:48:01.744Z

Reserved: 2026-09-14T13:37:05.263Z

Link: CVE-2026-90970

cve-icon Vulnrichment

Updated: 2026-10-02T16:47:56.719Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T15:17:12.550

Modified: 2026-10-02T18:44:11.270

Link: CVE-2026-90970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T15:30:12Z

Weaknesses
  • CWE-1336

    Improper Neutralization of Special Elements Used in a Template Engine