<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: 张读书</title>
    <description>The latest articles on DEV Community by 张读书 (@_9fd4158c45b4d88dcd8d6).</description>
    <link>https://dev.to/_9fd4158c45b4d88dcd8d6</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4172610%2F69770e7e-52c5-4f14-8b3c-7fdf3f014355.jpg</url>
      <title>DEV Community: 张读书</title>
      <link>https://dev.to/_9fd4158c45b4d88dcd8d6</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/_9fd4158c45b4d88dcd8d6"/>
    <language>en</language>
    <item>
      <title>GitLab AI Gateway CVE-2026-90970: "SSTI Wearing an AI Costume"</title>
      <dc:creator>张读书</dc:creator>
      <pubDate>Fri, 09 Oct 2026 06:13:17 +0000</pubDate>
      <link>https://dev.to/_9fd4158c45b4d88dcd8d6/gitlab-ai-gateway-cve-2026-90970-ssti-wearing-an-ai-costume-11d5</link>
      <guid>https://dev.to/_9fd4158c45b4d88dcd8d6/gitlab-ai-gateway-cve-2026-90970-ssti-wearing-an-ai-costume-11d5</guid>
      <description>&lt;p&gt;Disclosed: 2026-10-02. Sources: BleepingComputer (advisory quoted verbatim), The Hacker News, aiweekly, cyberpress, SecurityAffairs, ThaiCERT, dev.to/cortexflow_tech (patch guide), dennysentinel, forkast, labs.cosmicbytez. February CVE cross-checked against GitLab's own Feb 6, 2026 AI Gateway patch release (Greg Myers; text verified via archived mirror).&lt;br&gt;
TL;DR&lt;br&gt;
On October 2, GitLab disclosed CVE-2026-90970: a CVSS 9.9 sandbox escape in the AI Gateway's custom-flow prompt templates that lets an authenticated Duo Agent Platform user run arbitrary commands on the gateway. The uncomfortable part isn't the score — it's the déjà vu. Eight months earlier, GitLab patched CVE-2026-1868 in the same component, same CVSS 9.9, same CVSS vector, same weakness class (CWE-1336), via the same attack surface (a crafted Duo Agent Platform flow definition). They patched the hole in February. In October the sandbox broke again. And the exploit primitive isn't AI at all — it's server-side template injection, the vulnerability class backend engineers were patching a decade ago, now wearing an AI costume.&lt;br&gt;
The vulnerability (verified facts)&lt;br&gt;
CVE-2026-90970, CVSS 9.9 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H — network-reachable, low complexity, low privileges, no user interaction, changed scope, full C/I/A impact.&lt;br&gt;
Weakness: CWE-1336 — improper neutralization of special elements in a template engine.&lt;br&gt;
Mechanism: an authenticated user with Duo Agent Platform access submits a specially crafted flow configuration; inadequate sanitization lets it escape the prompt-template sandbox, yielding arbitrary command execution on the AI Gateway host/container.&lt;br&gt;
Affected: self-hosted AI Gateway 18.1.6–19.2.3, 19.3.0–19.3.1, 19.4.0. Fixed: 19.2.4, 19.3.2, 19.4.1 (released Oct 2).&lt;br&gt;
Scope: self-hosted gateways only. GitLab.com, GitLab Dedicated, and self-managed instances pointed at GitLab-hosted gateways were already remediated — no customer action needed.&lt;br&gt;
Disclosure: reported via HackerOne by researcher invisiblemeerkat; GitLab did targeted outreach to self-hosted gateway customers before the public advisory.&lt;br&gt;
Exploitation status: no public PoC, no known in-the-wild exploitation (CISA: none, as of Oct 2). No workaround exists.&lt;br&gt;
Why the gateway is the wrong box to lose&lt;br&gt;
The AI Gateway is the proxy every GitLab AI request passes through — code suggestions, chat, Duo Agent Platform flows. A self-hosted gateway is a trusted intermediary that holds JWT signing keys for GitLab↔gateway communication and maintains connections to both the internal GitLab instance and the organization's model providers. Command execution there isn't just a foothold; it's the signing keys and the traffic. Scope "changed" in the CVSS vector is doing real work here.&lt;br&gt;
Twice in eight months: the comparison that writes itself&lt;/p&gt;

&lt;p&gt;CVE-2026-1868 (Feb 2026)&lt;br&gt;
CVE-2026-90970 (Oct 2026)&lt;br&gt;
Component&lt;br&gt;
AI Gateway, Duo Workflow Service&lt;br&gt;
AI Gateway, custom-flow prompt templates&lt;br&gt;
CVSS&lt;br&gt;
9.9&lt;br&gt;
9.9&lt;br&gt;
Vector&lt;br&gt;
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H&lt;br&gt;
AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H&lt;br&gt;
CWE&lt;br&gt;
CWE-1336&lt;br&gt;
CWE-1336&lt;br&gt;
Attack surface&lt;br&gt;
Crafted Duo Agent Platform flow definition&lt;br&gt;
Crafted Duo Agent Platform flow configuration&lt;br&gt;
Impact&lt;br&gt;
DoS or code execution on the gateway&lt;br&gt;
Arbitrary command execution on the gateway&lt;br&gt;
Fixed in&lt;br&gt;
18.6.2 / 18.7.1 / 18.8.1&lt;br&gt;
19.2.4 / 19.3.2 / 19.4.1&lt;br&gt;
The February advisory (GitLab's own release post) described "insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions." The October advisory describes escaping "the prompt template sandbox via a specially crafted flow configuration." Different words, same sentence. The October advisory does not mention the February flaw.&lt;br&gt;
The technical angle: SSTI, not prompt injection&lt;br&gt;
This is the detail that makes the story land with a backend audience: the injection fires in the template engine, before any LLM is ever invoked. It is a server-side code-execution path, not an AI prompt-injection attack. Secondary technical write-ups (aiweekly, forkast, aiunderstanding) identify the engine as Jinja2-style placeholders; the official advisory itself only says "prompt template sandbox" and CWE-1336, so attribute the Jinja2 naming accordingly.&lt;br&gt;
There is a sharper data point from third-party analysis of the February CVE: a public PoC verification report traces it to ai_gateway/prompts/base.py and shows the fix introduced a PromptSandboxedEnvironment to replace the weaker sandbox. Read that plainly: in February, GitLab hardened the template sandbox. In October, the sandbox was escaped again through the same flow-definition surface. The patch fixed the instance; the design assumption — user-authored flow configs rendered by a template engine on trusted infrastructure — survived untouched.&lt;br&gt;
Operational gotchas worth one paragraph&lt;br&gt;
The AI Gateway is a separately versioned component. Upgrading core GitLab CE/EE does not remediate this; operators must update the gateway image/Helm chart directly. Multiple outlets flag this as the likeliest reason someone stays exposed.&lt;br&gt;
There is no workaround, and GitLab's advisory offers no way to determine whether a gateway was compromised before patching (THN). The update is the only remediation.&lt;br&gt;
The privilege bar is structural, not administrative: exploitation needs only the ability to author or edit a flow — not admin rights. Instances that let broad developer populations build custom Duo flows have a larger practical attack surface than "authenticated" suggests.&lt;br&gt;
Suggested blog angles (pick one)&lt;br&gt;
(a) "Patched the hole, not the thinking." Two 9.9s, eight months apart, identical vector, identical weakness class, identical attack surface — the recurrence is the editorial. Sandboxes around template engines are a 2015-era problem (SSTI has its own OWASP-era lore); bolting one onto an AI agent platform without rethinking who gets to author executable templates is how you get the same CVE twice. Connects directly to the Mods brief's "no sandbox ≈ handing out root" line — this time the vendor proved it against itself.&lt;br&gt;
(b) "SSTI wearing an AI costume" — the backend-developer resonance piece. Everything about the triage looks like AI security (prompt templates, agent platform, LLM gateway) and nothing about the exploit is AI security. For a Java/backend audience, that's the hook: the vulnerability class they fixed in their Spring/Thymeleaf apps a decade ago is now the thing breaking AI infrastructure. Pairs with the Mods/CVP material as an "AI-era dev-tool supply-chain security" mini-series.&lt;br&gt;
What's unverified / handle with care&lt;br&gt;
GitLab's official patch-release page text was verified only through verbatim quotes reproduced identically across BleepingComputer, SecurityAffairs, The Hacker News, and others — the page itself did not render in text fetch. Treat advisory wording as reported-by-outlets.&lt;br&gt;
The "Jinja2" engine naming comes from secondary technical analysis (aiweekly, forkast, aiunderstanding), not from GitLab's advisory, which says only "prompt template sandbox" / CWE-1336.&lt;br&gt;
The February PoC detail (base.py, SandboxedEnvironment → PromptSandboxedEnvironment) is from a third-party GitHub PoC verification repo, not from GitLab.&lt;br&gt;
No PoC and no known exploitation as of Oct 2–3 reporting; that can change — recheck before publishing.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>infosec</category>
      <category>security</category>
    </item>
  </channel>
</rss>
