---
id: CVE-2026-90970
title: >-
  GitLab has remediated a vulnerability in the GitLab AI Gateway component
  affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3
  before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could
  have allowed an…
summary: >-
  GitLab has remediated a vulnerability in the GitLab AI Gateway component
  affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3
  before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could
  have allowed an…
severity: critical
cvss: 9.9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-1336
vendor: GitLab
product: GitLab AI Gateway
affected:
  - ai_gateway >= 18.1.6 < 19.2.4
  - ai_gateway >= 19.3 < 19.3.2
  - ai_gateway >= 19.4 < 19.4.1
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T17:17:07.937'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-90970'
references:
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/work_items/628842'
    label: cve@gitlab.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-02T16:47:45.638880Z'
ingestedAt: '2026-10-02T15:21:27.999Z'
---

## Overview

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
