What to know
- The flaw can allow an authenticated user to escape a template sandbox.
- Fixed gateway versions are 19.2.4, 19.3.2 and 19.4.1.
- GitLab-hosted gateways do not require customer action.
The gateway has its own patch boundary
GitLab released AI Gateway versions 19.2.4, 19.3.2 and 19.4.1 to address CVE-2026-90970, rated 9.9. Under specified conditions, an authenticated user with Duo Agent Platform access could escape a custom-flow prompt-template sandbox and execute commands on the gateway. The affected ranges begin at 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. GitLab urges self-hosted gateway owners to update.
GitLab says it has already patched gateways it operates. That includes GitLab.com, Dedicated and self-managed instances using a GitLab-hosted gateway. The distinction is operationally important: running a self-managed GitLab instance does not by itself tell an administrator who operates the AI Gateway. The response starts by identifying the actual gateway deployment and its version.
Analysis: Prompts can reach conventional execution systems
The advisory illustrates a boundary that can be overlooked in AI architecture diagrams. A workflow definition may look like text supplied to a model, yet its preparation can pass through a template engine running on infrastructure with ordinary operating-system privileges. Security evaluation therefore needs to follow the entire path from a user-controlled definition to the process that handles it.
Calling the problem an AI flaw should not obscure the underlying responsibility. The model, orchestration service and gateway are separate components with separate attack surfaces. A safe evaluation asks which component interprets the configuration, what privileges it has and which inputs it accepts from different users. That is an architectural lesson from the published failure mode, not a claim that every custom-flow system shares this vulnerability.
Practical implications: Verify the gateway itself
Administrators should use GitLab’s linked update instructions for the gateway deployment they actually run and confirm the resulting version. Updating the main application without checking the gateway could leave the affected component unchanged. Teams should retain a record of the relevant installation and update, especially where another group owns the AI infrastructure.
The advisory does not establish that every affected instance was attacked, and it does not provide a universal incident conclusion. Patching closes the documented flaw; assessing earlier activity requires separate evidence and an appropriate investigation. For organizations building agents, the wider implication is to include template processors and orchestration services in asset inventories and patch ownership. A workflow’s natural-language interface does not remove the need to understand the conventional software that interprets it and the authority available when that interpretation fails.
An inventory entry should include the gateway image or chart, its running version and the team allowed to update it. That small operational record can prevent a security notice from being assigned to the wrong service owner.
Sources & further reading
Factual statements are grounded in the linked material. Interpretation and illustrative examples are Byte Watchr analysis. Vendor claims are identified as claims, rather than independent testing.
The event date records the source announcement or documented operation. The coverage edition groups recent developments and is separate from the publication date. Actual publication is recorded above.
Corrections policy · About this byline

