Zero Day Room
Live
Vulnerabilities

Critical RCE Flaw in Self-Hosted AI Gateway CVE-2026-90970

GitLab has patched a critical 9.9-rated RCE vulnerability, CVE-2026-90970, in its self-hosted AI Gateway.

Vulnerabilities: GitLab has patched a critical 9.9-rated RCE vulnerability, CVE-2026-90970, in its self-hosted AI Gateway

A critical remote code execution flaw, tracked as CVE-2026-90970, has been discovered in GitLab's self-hosted AI Gateway. The vulnerability, which carries a maximum CVSS score of 9.9 out of 10, allows arbitrary command execution on the underlying host server. Only self-hosted gateways are affected; GitLab runs AI Gateways for its customers and has already fixed them.

The flaw stems from insufficient sanitization of user-supplied flow configuration data. The gateway uses Jinja2-style template placeholders to process these configurations. An attacker can manipulate this template engine to perform a sandbox escape. Exploitation requires an authenticated user with basic privileges and access to the Duo Agent Platform. No user interaction is needed.

Impact and risk

Compromise of this component poses a severe threat. The AI Gateway acts as a central hub within the GitLab ecosystem. It holds sensitive JWT signing keys and manages connections to both internal and external AI model providers. An attacker gaining control would have command over an organization's AI-integrated workflows and authentication tokens. The barrier to entry is relatively low, requiring only basic user privileges and Duo Agent Platform access.

Mitigation and response

Self-hosted operators must manually update their installations to a patched version. GitLab has issued fixed versions for multiple release lines. The company strongly recommends immediate action.

Fixed Version
19.2.4
19.3.2
19.4.1

No fixed version exists below 19.2.4. The flaw affects AI Gateway versions from 18.1.6 up to, but not including, the patched releases. GitLab said, "we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately."

Context and similar risks

This failure to properly isolate a template engine is not an isolated incident. Similar risks have surfaced in other campaigns, including Langflow credential harvesting operations and Cisco SD-WAN authentication bypass vulnerabilities. The GitLab flaw is formally filed under the common weakness enumeration CWE-1336. Researcher Joern Schneeweisz identified a related high-severity vulnerability, CVE-2026-1868, which also carried a CVSS 9.9 rating and involved CWE-1336, in February 2026.

Current status

As of now, there is no evidence of active exploitation. The U.S. Cybersecurity and Infrastructure Security Agency added an assessment to the CVE record on October 2, 2026, stating the exploitation status was 'none.' No public proof-of-concept exploit has been published. The situation remains stable but urgent. Self-hosted operators must manually update to versions 19.2.4, 19.3.2, or 19.4.1 to fix the vulnerability.

Related coverage

More from Vulnerabilities