Skip to content

Security2 publishers2 min readPublished

GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

GitLab patched CVE-2026-90970, a sandbox escape that lets any authenticated Duo Agent Platform user run arbitrary commands on a self-hosted AI Gateway. Customers on GitLab's hosted gateway are already protected, so the upgrade falls to Self-Managed shops that run their own.

The Watch · Security desk

Illustration accompanying GitLab patches sandbox escape that lets Duo agent users run commands on self-hosted AI Gateways

What happened

  • BleepingComputer reports the flaw is an improper neutralization weakness that needs only basic privileges on top of Duo Agent Platform access.
  • GitLab says it contacted Self-Hosted AI Gateway customers with upgrade guidance before it published the release post.
  • CISA has flagged five GitLab vulnerabilities as exploited in the wild since November 2021, one of them by ransomware gangs.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • exposure Any account holding a Duo Agent Platform seat, whether an insider's or one taken over with stolen credentials, is enough to reach command execution on a self-hosted gateway.
  • cost Fixes ship on three release lines, so a self-hosted gateway on 19.2, 19.3 or 19.4 can be patched within its current line.
  • precedent GitLab's previous critical went from patch to a federal deadline in four days, one to reach CISA's exploited list and three more for agencies. A listing for this flaw would start a similar clock.

GitLab's Friday advisory [12] said the flaw "under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway" [4]. The attacker's input is a flow configuration, submitted with access the attacker already holds [4]. Those commands run on the gateway, the service that gives access to GitLab Duo's AI features [2].

Only part of GitLab's user base is exposed. GitLab reports more than 30 million registered users and use at over half of the Fortune 100 [11]. Its own cloud gateway serves GitLab.com, Self-Managed and Dedicated customers. The vulnerable installs are the separate gateways that Self-Managed customers deploy themselves through GitLab Duo Self-Hosted [2]. BleepingComputer's report does not say how many such gateways exist, or that CVE-2026-90970 has been exploited [13].

For operators who do run one, the instruction is to upgrade now. "These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately," the company said [7].

Last month's critical is the comparison point. CVE-2026-85706, a maximum-severity path traversal in GitLab Community and Enterprise Edition, let unauthenticated attackers read credentials and other secrets from servers [8]. CISA added it to its actively exploited list under BOD 26-04 [9]. That bug needed no login. This one needs a logged-in user with agent access [4]. In return it gives command execution on the gateway, where last month's bug gave reads of stored secrets [4][8].

What to watch

  • A CISA listing of CVE-2026-90970 as actively exploited, and the BOD 26-04 deadline attached to it.
  • Public detail on the "certain conditions" GitLab cites, or a proof of concept for the crafted flow configuration.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories