DEV Community

Anoymask
Anoymask

Posted on

GitLab AI Gateway CVE-2026-90970: Authenticated Command Execution via Prompt Template Sandbox Escape

1. Basic Information

  • Original Title: GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1
  • Source: GitLab
  • Publication Date: October 2, 2026
  • Updated Date: None
  • Severity: Critical
  • Severity Basis: The CVSS v3.1 score is 9.9. Exploitation requires an authenticated GitLab user with access to the Duo Agent Platform and can lead to arbitrary command execution on the AI Gateway. Administrators of affected self-hosted AI Gateway instances must apply updates. GitLab has already deployed the fix to GitLab-hosted AI Gateways.
  • Source Link: GitLab
  • Related Sources: BleepingComputer, GitLab AI Gateway installation guide
  • Associated Malware: None
  • Associated Threat Groups: None
  • Associated CVE: CVE-2026-90970
  • Affected Products: GitLab Self-Hosted AI Gateway, GitLab Duo Agent Platform

2. Summary

On self-hosted GitLab AI Gateway instances, an authenticated user with access to the Duo Agent Platform can supply a crafted flow configuration to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway.

3. Attack Flow

Flow 1: From Authenticated User to AI Gateway Command Execution

  1. The attacker is authenticated on a GitLab instance using an affected version of Self-Hosted AI Gateway and holds permissions to access the Duo Agent Platform.
  2. The attacker submits a crafted flow configuration targeting prompt template processing to the AI Gateway. Specific fields have not been disclosed.
  3. Inadequate sanitization allows the attacker to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway.
  4. Inference: Subsequent impact depends on the execution privileges of the Gateway container, secrets, mount settings, and network reachability.

4. Attacker Position and Execution Location

  • The attacker is an authenticated GitLab user with access to the Duo Agent Platform.
  • Commands are executed on the Self-Hosted AI Gateway service.

5. Visibility for Victims and Administrators

Victims

  • Operations may appear consistent with normal GitLab Duo usage. No explicit warnings or interface changes for users have been disclosed.

Administrators

  • Inference: Potential indicators include suspicious custom flow creation or modification, AI Gateway errors, unexpected child processes, and outbound connections to destinations outside those expected for the deployment. Specific log fields and IoCs for this vulnerability have not been disclosed.

6. Success and Failure Conditions

Success Conditions

  • The target runs an affected version of Self-Hosted AI Gateway.
  • The attacker is authenticated in GitLab and has access to the Duo Agent Platform.
  • The crafted flow configuration is processed successfully, achieving sandbox escape.

Failure Conditions

  • The system is updated to the patched version corresponding to the deployment series (19.2.4 or later for 19.2, 19.3.2 or later for 19.3, and 19.4.1 or later for 19.4). When migrating from older series, verify compatibility with the core GitLab installation and apply the correct patch tags.
  • The deployment uses the GitLab-hosted AI Gateway, where patches are already applied.
  • Restricting access to the Duo Agent Platform and halting suspicious flows serve as temporary risk mitigation steps, but do not guarantee protection against the abuse of legitimate accounts, making patch application necessary.

7. Impact Upon Success

  • Execution of arbitrary commands on the AI Gateway.
  • Inference: Access to JWT signing keys, model provider credentials, GitLab connection details held or referenced by the Gateway, or lateral movement to reachable services.

8. Observable Logs

Email

  • There are no email logs specific to this issue.

Proxy / SWG / DNS

  • Review logs for new outbound connections from the AI Gateway to destinations other than the GitLab instance, model providers, and customers.gitlab.com.

Endpoint / EDR

  • Check if shells, interpreters, or download utilities are spawned from service processes on the AI Gateway container or host.

Identity / IdP

  • Verify user sign-ins, sessions, and the grant or modification history of Duo Agent Platform access privileges.

SaaS / Cloud

  • Check for the creation or modification of custom flows, access to AI Gateway APIs, GitLab audit events, and container orchestration events.

Network

  • Review source addresses for connections to ports 5052 and 50052, along with outbound connections from the Gateway. Visibility into request content depends on the monitoring point, where TLS is terminated, and the logging configuration.

9. Attack Success Determination

Confirm Initial Execution

  • Public Information and Criteria: GitLab's advisory describes the possibility of arbitrary command execution but does not report exploitation in the wild. Assessment criteria: Use process execution records or audit logs to confirm that attacker-controlled commands executed within the AI Gateway service in connection with a crafted flow configuration. Unusual child processes or errors alone do not establish successful exploitation.
  • Scope: Self-Hosted GitLab AI Gateway
  • Associated CVE: CVE-2026-90970

10. Investigation Playbook

Trigger

  • Focus on affected versions, suspicious users with access to the Duo Agent Platform, modified custom flows, child processes spawned by the Gateway, or unknown outbound connections.

Initial Checks

  • Verify the AI Gateway image version, whether the deployment is GitLab-hosted or Self-Hosted, user privileges, exposure scope, and patch application timestamps.

Endpoints

  • Preserve container images and temporary files, along with available container runtime records, process trees, and telemetry showing environment-variable access or shell activity.

Identity and Cloud

  • Check user sessions, access tokens, Duo Agent Platform privileges, JWT signing keys, and the usage of model provider credentials.

Subsequent Actions

  • Track connections from the Gateway to the GitLab API, model providers, internal services, and external hosts, as well as the use of secrets.

Containment

  • Suspend the affected flow and account, restrict Gateway network access, and update to the patched version. If compromise is confirmed, rotate Gateway keys and credentials after assessing the impact.

Determination Categories

  • Document findings by categorizing the presence of vulnerable configurations, exploit attempts, command execution, secret access, and lateral movement.

11. Defense and Detection Ideas

Single Events

  • Treat the spawning of shells or system utilities from the AI Gateway service as a high-priority event.

Timeline Correlation

  • Correlate custom flow modifications, AI Gateway API access, child process generation, and unknown outbound connections or secret usage as a continuous attack sequence.

Hunting Perspectives

  • Retroactively review flow history during the affected period, Duo Agent Platform usage, container processes, and network connections.

Log Gaps

  • Specific payloads and standard log fields have not been disclosed. Combine container runtime and network telemetry rather than relying solely on application logs.

Priority Mitigations

  • Prioritize updating to patched versions, enforcing the principle of least privilege for Duo Agent Platform access, allowlisting outbound connections, and protecting JWT and model credentials.

12. Facts, Inference, and Hypothesis

Facts

  • GitLab disclosed CVE-2026-90970 as an improper sanitization vulnerability in prompt template processing for custom flows.
  • An authenticated user with access to the Duo Agent Platform can supply a crafted flow configuration to escape the prompt template sandbox and execute arbitrary commands on the AI Gateway.
  • Affected versions are 18.1.6 or later but earlier than 19.2.4; 19.3.0 or later but earlier than 19.3.2; and 19.4.0 or later but earlier than 19.4.1. The fixes were released in versions 19.2.4, 19.3.2, and 19.4.1.
  • GitLab-hosted AI Gateway instances already have the fix deployed, meaning GitLab.com, GitLab Dedicated, and self-managed environments using the GitLab-hosted AI Gateway require no additional action.
  • Public documentation reports no active exploitation or compromise incidents.

Inference

  • If an attacker successfully executes commands inside the AI Gateway container, the impact will depend on network reachability to configured GitLab instances or model providers, environment variables, mount settings, and service accounts. Public documentation does not specify subsequent attacker actions.
  • Restricting outbound AI Gateway traffic exclusively to the GitLab instance, model providers, and license verification endpoints helps suppress and detect external C2 or additional payload retrieval following command execution.

Hypothesis

No additional hypotheses. Unconfirmed items are listed in "14. Unresolved Questions and Further Investigation".

13. MITRE ATT&CK Mapping

ID Technique Confidence Basis
T1059 Command and Scripting Interpreter medium Inferred mapping based on the arbitrary command execution described by GitLab. Specific use of shells or interpreters and exploitation in the wild remain unconfirmed.

14. Unresolved Questions and Further Investigation

  • Specific fields and payloads of the crafted flow configuration.
  • The user context under which commands execute, container privileges, and fields recorded in standard audit and application logs.
  • Evidence of active exploitation in the wild and known IOCs.

15. Impact on SOCs and Organizations

Japanese organizations using GitLab Duo Self-Hosted in their development environments should verify both the core GitLab version and the AI Gateway image tag. Isolate AI feature usage permissions from general users, and monitor flow creation, modifications, Gateway process creation, and outbound connections within a unified timeline.

16. Summary by Role

  • SOC: Correlate flow configuration changes, AI Gateway APIs, container processes, and outbound connections to distinguish normal model invocations from command execution.
  • Administrators: Update Self-Hosted AI Gateway instances to the patched version corresponding to the deployment series (19.2.4, 19.3.2, 19.4.1, or later) and verify compatibility with core GitLab. Minimize Duo Agent Platform access privileges and Gateway outbound traffic.
  • Users: Users of the GitLab-hosted AI Gateway require no additional action. Self-hosted environments must follow administrator update guidance.

Top comments (0)