GitLab has issued an urgent warning to customers regarding a critical remote code execution (RCE) vulnerability, identified as CVE-2026-90970, affecting its AI Gateway service. The flaw could allow attackers to execute arbitrary commands on vulnerable self-hosted instances.
The AI Gateway is a component that provides access to GitLab Duo's AI-native features. While GitLab operates its own cloud-based AI Gateway for GitLab.com, GitLab Self-Managed, and GitLab Dedicated, users also have the option to deploy self-hosted instances on GitLab Self-Managed through GitLab Duo Self-Hosted.
The vulnerability stems from an improper neutralization weakness. An authenticated user with basic privileges and Duo Agent Platform access could exploit this flaw by crafting a special flow configuration to escape the prompt template sandbox, leading to arbitrary command execution on the AI Gateway.
GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1 to address CVE-2026-90970 for users of self-hosted AI Gateway installations. The company strongly recommends that all GitLab Self-Managed customers with self-hosted AI Gateway installations update to one of these versions immediately. Customers utilizing a GitLab-hosted AI Gateway are already protected and do not need to take any action. GitLab confirmed that it conducted targeted outreach to self-hosted AI Gateway customers prior to the public disclosure of the vulnerability.
This alert follows a recent patch for a maximum severity path traversal vulnerability, CVE-2026-85706, in GitLab Community Edition (CE) and Enterprise Edition (EE). That flaw allowed unauthenticated attackers to read sensitive data, including credentials and other secrets, from vulnerable servers. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) subsequently added CVE-2026-85706 to its catalog of actively exploited vulnerabilities, mandating federal agencies to secure their systems within three days.
Since November 2021, CISA has identified five GitLab vulnerabilities that have been exploited in the wild, with one instance linked to ransomware attacks. GitLab's DevSecOps platform serves over 30 million registered users, including more than 50% of Fortune 100 companies.






