
GitLab CVE-2026-90970 Enables RCE on Self-Hosted AI Gateways via Duo Custom Flow Template Escape
GitLab addressed a second CVSS 9.9 template escape in its self-hosted AI Gateway within eight months. The flaw affects only organizations running their own gateway and stems from insufficient sandboxing in Duo custom flows. Pattern indicates systemic issues in the gateway's prompt handling that official advisories continue to under-document.
The vulnerability resides in custom flow prompt templates on the Duo Agent Platform. A logged-in user with access can submit a crafted configuration that breaks the sandbox, yielding command execution on the gateway container or Helm deployment. The gateway handles JWT signing keys and direct connections to internal model providers, making any compromise high-impact for data exfiltration or lateral movement. GitLab fixed the issue in 19.2.4, 19.3.2, and 19.4.1; earlier lines remain unpatched with no listed workarounds.
CISA recorded exploitation as none on October 2. The flaw shares CWE-1336 with February's CVE-2026-1868, also rated 9.9 and triggered by crafted flow definitions. Both point to recurring template-engine weaknesses in the gateway's AI orchestration layer. Self-hosted gateways were explicitly marketed for data residency, yet the same component now carries repeated critical remote code risks without public proof-of-concept or attack surface details.
GitLab's maintenance policy aligns fixes only with currently supported minor releases, leaving organizations on 19.1 or earlier without a clear upgrade path that preserves feature parity. Procurement records show rising adoption of self-hosted gateways among regulated sectors seeking to avoid cloud model routing. The absence of post-update integrity checks or logging recommendations increases the chance that prior template escapes go undetected.
Administrators should treat the gateway image as a high-value asset requiring immediate isolation and monitoring. Expect follow-on patches if compatibility testing reveals that 19.2.4+ images cannot safely pair with older GitLab cores.
GitLab: At least one public PoC for CVE-2026-90970 will appear on GitHub within 21 days.
Sources (3)
- [1]GitLab Security Advisory(https://about.gitlab.com/security/cve-2026-90970/)
- [2]NVD CVE Record(https://nvd.nist.gov/vuln/detail/CVE-2026-90970)
- [3]The Hacker News Report(https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html)