GitLab's AI Agent Gateway Had a 9.9 Flaw That Let Logged-In Duo Users Escape a Prompt Sandbox and Run Commands
The companies that self-host GitLab's AI to keep their data in-house are the only ones exposed to a critical sandbox escape, and it is the second 9.9 bug of its kind in the same component this year.

GitLab has patched a critical hole in the piece of software that sits between its developer platform and the AI models behind GitLab Duo. The flaw, CVE-2026-90970, scores 9.9 out of 10 and let a logged-in user break out of a sandbox and run commands on the server.
The component is the AI Gateway, which handles Duo's code suggestions, chat and agentic workflows. GitLab disclosed the bug on October 2.
A sandbox that leaked
According to the advisory, the bug "could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway." Flows are the multi-step AI workflows users build on the Duo Agent Platform, and the hole sat in the prompt template of a custom flow. The weakness class is improper neutralization in a template engine (CWE-1336).
The sandbox exists precisely to keep user-written AI workflows away from the machine. It failed anyway.
The irony is who is exposed. GitLab already fixed its own hosted gateways, so GitLab.com, GitLab Dedicated and self-managed instances using a GitLab-hosted gateway need do nothing. Only organizations running GitLab Duo Self-Hosted are at risk, the customers who chose to run the gateway themselves to keep AI requests and responses inside their own infrastructure.
Why the gateway matters
A self-hosted gateway is not a throwaway box. It holds the signing keys for JSON Web Tokens, passed in as environment variables that GitLab says must be treated as sensitive credentials, and it talks to both the GitLab instance and the organization's AI model providers. Command execution there is a foothold inside infrastructure that handles AI traffic and authentication.
Fixed gateway versions are 19.2.4, 19.3.2 and 19.4.1, and GitLab "strongly recommend[s]" that self-hosted customers update immediately. It reached out to them directly before publishing. There is no fix listed below 19.2.4, which leaves releases from 18.1.6 through the 19.1 line in the affected range. GitLab offers no workaround, no way to check whether a gateway was hit before patching, and no detail on the exact conditions or required role beyond Duo Agent Platform access.
GitLab does not say the flaw has been exploited, and CISA's assessment on the CVE record lists exploitation as "none." The bug was reported through HackerOne by a researcher going by invisiblemeerkat.
Second time this year
This has happened before. In February, GitLab fixed another 9.9 gateway flaw, CVE-2026-1868, also reachable through a crafted flow definition and filed under the same weakness class. The new advisory does not mention it.
It is also not GitLab's only critical bug lately. Last month the company patched a maximum-severity path traversal flaw, CVE-2026-85706, in its Community and Enterprise editions, and CISA added it to its actively exploited list a day later. We have also covered an earlier critical GraphQL flaw in GitLab. CISA has tagged five GitLab flaws abused in the wild since November 2021, one by ransomware gangs, on a platform with more than 30 million registered users and over half the Fortune 100.
AI sandboxes keep proving softer than advertised, from GitLab's flows to the HeapJack escape in OpenAI's Codex. For self-hosted Duo shops, the fix is out, and the gateway version number is what matters now.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free