Skip to content

Build1 publisherNot yet confirmed elsewhere2 min readPublished

GitLab patches a second CVSS 9.9 template-sandbox escape in its AI Gateway in eight months

GitLab has fixed CVE-2026-90970, a CVSS 9.9 sandbox escape that lets an authenticated Duo Agent Platform user run commands on self-hosted AI Gateways. Anyone running one of those gateways needs build 19.2.4, 19.3.2 or 19.4.1, all released October 2, to close it.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying GitLab patches a second CVSS 9.9 template-sandbox escape in its AI Gateway in eight months
Generated illustration

What happened

  • In February GitLab patched CVE-2026-1868 in the same AI Gateway, with the same 9.9 score, the same CVSS vector and the same CWE-1336 template-injection weakness class.
  • The injection fires in the template engine before any language model is invoked, so it is server-side template injection and not a prompt-injection attack, per the dev.to analysis.
  • As of October 2 there was no public proof of concept and no known in-the-wild exploitation, and GitLab lists no workaround for the flaw.
  • A researcher using the handle invisiblemeerkat reported the flaw to GitLab through its HackerOne program.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Command execution on a self-hosted gateway reaches the JWT signing keys for GitLab-to-gateway traffic and the gateway's connections to the internal GitLab instance and the organization's model providers.
  • decision A February upgrade leaves this bug open, so self-hosted operators need one of the October 2 builds no matter what they patched earlier in the year.
  • constraint Model-side prompt-injection filters cannot see this path because the payload runs while the template renders. Until the upgrade lands, the practical control is who holds Duo Agent Platform access.
  • precedent A second escape after February's sandbox hardening argues for treating custom-flow prompt templates as code that users submit to the server, with the same review and permissions as code.

GitLab's February fix for CVE-2026-1868 shipped in AI Gateway 18.6.2, 18.7.1 and 18.8.1, in a patch release dated February 6, according to a dev.to write-up that checked both advisories against each other [12]. October's advisory lists self-hosted builds 18.1.6 through 19.2.3 as affected, along with 19.3.0 to 19.3.1 and 19.4.0 [5]. All three February builds fall inside that first range [20]. GitLab's own version list therefore shows the October bug was already present in the builds that carried the February fix [20].

The attack path is short. A user with Duo Agent Platform access submits a crafted flow configuration [4]. The gateway expands it inside its prompt-template sandbox. Inadequate sanitization then lets the payload out to run commands on the gateway host or container [4]. The vector string matches that description: network-reachable, low complexity, low privileges, no user interaction [2]. GitLab's advisory says only "prompt template sandbox" and cites CWE-1336, improper neutralization of special elements in a template engine [17][3]. According to the same write-up, the claim that the engine uses Jinja2-style placeholders comes from secondary coverage, not from GitLab [17].

February's repair was a sandbox repair. A third-party PoC verification report, cited in the same analysis, traces CVE-2026-1868 to ai_gateway/prompts/base.py and shows the fix replacing a weaker sandbox with a class called PromptSandboxedEnvironment [18]. GitLab's October advisory does not mention the February flaw. So the public record does not say whether the new escape defeats that class or gets around it [15].

The advisory wording barely changed. In February GitLab wrote of "insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions" [13]. In October it wrote of escaping "the prompt template sandbox via a specially crafted flow configuration" [14]. Both advisories give the same CVSS string, "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", character for character [2][11].

GitLab handled the disclosure well. GitLab.com, GitLab Dedicated and self-managed instances that point at GitLab-hosted gateways were remediated before the advisory and need no action [6]. GitLab also contacted self-hosted gateway customers directly before going public [19]. That leaves self-hosted gateways as the exposed set. In those deployments every GitLab AI request, including code suggestions, chat and Duo Agent Platform flows, passes through the box an attacker would own [9].

What to watch

  • A public proof of concept or a CISA exploitation listing for CVE-2026-90970 would turn a scheduled upgrade into incident response for self-hosted gateway operators.
  • A technical write-up from GitLab or the reporter showing whether the October escape defeats PromptSandboxedEnvironment or uses a separate path.
  • Any change GitLab makes to how custom-flow prompt templates are authored or rendered, beyond another sandbox patch.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence62
Adoption
Insufficient
Hype gap+12
Incentives30
Confidence58
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    On October 2, 2026, GitLab disclosed CVE-2026-90970, a CVSS 9.9 sandbox escape in the AI Gateway's custom-flow prompt templates that lets an authenticated Duo Agent Platform user run arbitrary commands on the gateway.

    ReportedSupportedSource: dev.to analysis quoting GitLab's advisory via BleepingComputerView cited source
  2. [2]

    CVE-2026-90970 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-reachable, low complexity, low privileges, no user interaction, changed scope, full confidentiality, integrity and availability impact.

    ReportedSupportedSource: dev.to analysisView cited source
  3. [3]

    The weakness is CWE-1336, improper neutralization of special elements in a template engine.

    ReportedSupportedSource: dev.to analysisView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 8, 2026

    GitLab AI Gateway CVE-2026-90970: "SSTI Wearing an AI Costume"

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Topics

  • Server-side template injectionFollow
  • AI developer tooling securityFollow

Entities

Loading related stories