GitLab has released patches for CVE-2026-90970, a critical vulnerability affecting the GitLab AI Gateway. With a CVSS score of 9.9, the flaw allows an authenticated user with Duo Agent Platform access to achieve arbitrary command execution on the underlying host. This is the first critical remote code execution vulnerability identified in an AI-specific infrastructure component.
The vulnerability, classified under CWE-1336, stems from insufficient sanitization of user-supplied flow configuration data. The AI Gateway uses Jinja2-style template placeholders to process these configurations. Because the input is not properly neutralized, an attacker can manipulate the template engine to perform a sandbox escape. By breaking out of the intended execution context, the attacker gains the ability to execute commands directly on the host operating system.
The failure to isolate the template engine is not unique to GitLab. It fits the trust-through-defaults pattern-components deployed with insufficient security boundaries around user-controllable inputs. This pattern has appeared in recent incidents including the OpenAI Misalignment Portal DNS sandbox escape and the DIVD Zammad breach, where agents exploited zero-days to bypass intended restrictions. Similar risks have surfaced in Langflow credential harvesting campaigns and Cisco SD-WAN authentication bypasses.
For organizations operating self-hosted instances, the implications are concrete. The AI Gateway acts as a central hub within the GitLab ecosystem, holding sensitive JWT signing keys and managing connections to both internal GitLab instances and external AI model providers. A compromise of this component gives an attacker control over an organization’s AI-integrated workflows and authentication tokens. While GitLab-hosted instances have been patched, self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1.
The history of this component suggests the issue is not isolated. In February 2026, Joern Schneeweisz identified CVE-2026-1868, a vulnerability in the same Duo Workflow Service component. That earlier flaw also involved CWE-1336 and carried a CVSS 9.9 rating. The recurrence of this vulnerability class within the same infrastructure layer indicates that the template-engine sandbox boundary remains a persistent point of failure for AI agent platforms.
As of October 3, 2026, there is no evidence of exploitation in the wild, and no public proof-of-concept exploit has been published. CISA assessed the exploitation status as none on October 2. However, the absence of a known exploit does not reduce the severity for self-hosted environments. There is no available workaround, and no reliable method exists to determine whether a gateway was compromised before patching. The update is the only effective remediation.
Security professionals monitoring AI infrastructure should focus on two primary isolation challenges. The first is the template-engine sandbox boundary, which is the focus of this CVE. The second is the agent capability and tool boundary, which governs how agents interact with external systems. As recent research shows, the rate at which AI infrastructure vulnerabilities are being identified is accelerating.
GitLab conducted targeted outreach to self-hosted customers before publishing the advisory, reflecting the sensitivity of the component. The Duo Workflow Service has now produced two CVSS 9.9 template-engine escapes in eight months. That recurrence rate-not the absence of a known exploit-is what should set the timeline for self-hosted operators still running unpatched gateways.
