Back

GitLab Urges Immediate Patch for Critical AI Gateway Vulnerability

At a glance

  • GitLab identified a critical security flaw in its AI Gateway service.
  • Patched versions 19.2.4, 19.3.2, and 19.4.1 have been released.
  • Self-hosted instances running older versions remain at risk.

On October 2, 2026, GitLab notified customers about a critical security issue affecting its AI Gateway service, prompting an immediate update to address the vulnerability.

The vulnerability, catalogued as CVE-2026-90970, involves an improper neutralization weakness that could allow an authenticated user with Duo Agent Platform access to bypass the prompt template sandbox. This could result in the execution of arbitrary commands on systems that have not applied the patch.

To mitigate the risk, GitLab released updated versions of the AI Gateway software. The company stated that versions 19.2.4, 19.3.2, and 19.4.1 contain the necessary fixes to resolve the identified issue.

According to GitLab, the vulnerability affects self-hosted AI Gateway instances that are running software versions earlier than the patched releases. The company also stated that GitLab-hosted AI Gateway environments have already been secured and require no further action from users.

What the numbers show

  • The vulnerability was disclosed on October 2, 2026.
  • Patched versions released: 19.2.4, 19.3.2, and 19.4.1.
  • The CVSS score assigned to the flaw is 9.9.

The security issue is classified as a remote code execution vulnerability, which means an attacker could potentially run commands on affected systems if the patch is not applied. The flaw specifically impacts users with Duo Agent Platform access on unpatched installations.

GitLab's documentation indicates that only self-hosted deployments of the AI Gateway are vulnerable if they have not been updated to the latest versions. Customers using the cloud-hosted version of the service are not exposed to this risk, according to the company's statement.

The company emphasized the urgency of applying the available patches to prevent the exploitation of this vulnerability. GitLab provided guidance on how to update affected systems to the secure versions.

Security professionals and administrators responsible for self-hosted AI Gateway deployments have been advised to review their current software versions and implement the recommended updates as soon as possible to ensure protection.

* This article is based on publicly available information at the time of writing.