GitLab fixes a flaw that lets AI workflows escape their sandbox
GitLab has disclosed a critical flaw in AI Gateway that lets an authenticated Duo Agent Platform user run arbitrary commands through a crafted workflow template. The company has patched gateways it hosts. Organizations operating their own gateways must install a corrected version; the advisory separates those installations from customers using GitLab’s managed service.
Artificial Intelligence··Evening
A workflow template can reach the gateway host
GitLab has disclosed a sandbox escape in AI Gateway, the service used for its Duo AI features. An authenticated user with access to Duo Agent Platform, GitLab’s system for running AI workflows, can supply a specially crafted flow template and execute arbitrary commands on the gateway. The issue is tracked as CVE-2026-90970.[1], [2]
Three maintained branches have corrected versions
GitLab rates the flaw critical and assigns it a vulnerability severity score of 9.9. Affected gateway releases begin at 18.1.6 and run to versions before 19.2.4; the 19.3 branch is affected before 19.3.2 and the 19.4 branch before 19.4.1. Those three endpoint versions contain the fixes. The published assessment describes network access, low attack complexity and low privileges, with no user interaction required.[1]
Hosted gateways have already been patched
GitLab has already patched the AI Gateways it hosts. Customers using GitLab.com, GitLab Dedicated, or a self-managed installation connected to GitLab’s hosted gateway do not need an additional gateway update for this issue. Administrators hosting AI Gateway themselves are asked to update their service.[1]
The company says it contacted affected customers before public disclosure. It credits the researcher invisiblemeerkat with reporting the vulnerability. The public notice distinguishes disclosure of the flaw from the earlier distribution of the corrected software.[1]