Build1 publisherNot yet confirmed elsewhere2 min readPublished
GitLab patches a second CVSS 9.9 template-sandbox escape in its AI Gateway in eight months
GitLab has fixed CVE-2026-90970, a CVSS 9.9 sandbox escape that lets an authenticated Duo Agent Platform user run commands on self-hosted AI Gateways. Anyone running one of those gateways needs build 19.2.4, 19.3.2 or 19.4.1, all released October 2, to close it.
The Engineer · Build desk

What happened
- In February GitLab patched CVE-2026-1868 in the same AI Gateway, with the same 9.9 score, the same CVSS vector and the same CWE-1336 template-injection weakness class.
- The injection fires in the template engine before any language model is invoked, so it is server-side template injection and not a prompt-injection attack, per the dev.to analysis.
- As of October 2 there was no public proof of concept and no known in-the-wild exploitation, and GitLab lists no workaround for the flaw.
- A researcher using the handle invisiblemeerkat reported the flaw to GitLab through its HackerOne program.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure Command execution on a self-hosted gateway reaches the JWT signing keys for GitLab-to-gateway traffic and the gateway's connections to the internal GitLab instance and the organization's model providers.
- decision A February upgrade leaves this bug open, so self-hosted operators need one of the October 2 builds no matter what they patched earlier in the year.
- constraint Model-side prompt-injection filters cannot see this path because the payload runs while the template renders. Until the upgrade lands, the practical control is who holds Duo Agent Platform access.
- precedent A second escape after February's sandbox hardening argues for treating custom-flow prompt templates as code that users submit to the server, with the same review and permissions as code.
GitLab's February fix for CVE-2026-1868 shipped in AI Gateway 18.6.2, 18.7.1 and 18.8.1, in a patch release dated February 6, according to a dev.to write-up that checked both advisories against each other [12]. October's advisory lists self-hosted builds 18.1.6 through 19.2.3 as affected, along with 19.3.0 to 19.3.1 and 19.4.0 [5]. All three February builds fall inside that first range [20]. GitLab's own version list therefore shows the October bug was already present in the builds that carried the February fix [20].
The attack path is short. A user with Duo Agent Platform access submits a crafted flow configuration [4]. The gateway expands it inside its prompt-template sandbox. Inadequate sanitization then lets the payload out to run commands on the gateway host or container [4]. The vector string matches that description: network-reachable, low complexity, low privileges, no user interaction [2]. GitLab's advisory says only "prompt template sandbox" and cites CWE-1336, improper neutralization of special elements in a template engine [17][3]. According to the same write-up, the claim that the engine uses Jinja2-style placeholders comes from secondary coverage, not from GitLab [17].
February's repair was a sandbox repair. A third-party PoC verification report, cited in the same analysis, traces CVE-2026-1868 to ai_gateway/prompts/base.py and shows the fix replacing a weaker sandbox with a class called PromptSandboxedEnvironment [18]. GitLab's October advisory does not mention the February flaw. So the public record does not say whether the new escape defeats that class or gets around it [15].
The advisory wording barely changed. In February GitLab wrote of "insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions" [13]. In October it wrote of escaping "the prompt template sandbox via a specially crafted flow configuration" [14]. Both advisories give the same CVSS string, "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H", character for character [2][11].
GitLab handled the disclosure well. GitLab.com, GitLab Dedicated and self-managed instances that point at GitLab-hosted gateways were remediated before the advisory and need no action [6]. GitLab also contacted self-hosted gateway customers directly before going public [19]. That leaves self-hosted gateways as the exposed set. In those deployments every GitLab AI request, including code suggestions, chat and Duo Agent Platform flows, passes through the box an attacker would own [9].
What to watch
- A public proof of concept or a CISA exploitation listing for CVE-2026-90970 would turn a scheduled upgrade into incident response for self-hosted gateway operators.
- A technical write-up from GitLab or the reporter showing whether the October escape defeats PromptSandboxedEnvironment or uses a separate path.
- Any change GitLab makes to how custom-flow prompt templates are authored or rendered, beyond another sandbox patch.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+12
- Incentives30
- Confidence58
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
On October 2, 2026, GitLab disclosed CVE-2026-90970, a CVSS 9.9 sandbox escape in the AI Gateway's custom-flow prompt templates that lets an authenticated Duo Agent Platform user run arbitrary commands on the gateway.
ReportedSupportedSource: dev.to analysis quoting GitLab's advisory via BleepingComputerView cited source - [2]
CVE-2026-90970 vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-reachable, low complexity, low privileges, no user interaction, changed scope, full confidentiality, integrity and availability impact.
- [3]
The weakness is CWE-1336, improper neutralization of special elements in a template engine.
- [4]
An authenticated user with Duo Agent Platform access submits a specially crafted flow configuration; inadequate sanitization lets it escape the prompt-template sandbox, yielding arbitrary command execution on the AI Gateway host or container.
- [5]
Affected: self-hosted AI Gateway 18.1.6-19.2.3, 19.3.0-19.3.1, 19.4.0. Fixed: 19.2.4, 19.3.2, 19.4.1, released October 2.
- [6]
Only self-hosted gateways are affected; GitLab.com, GitLab Dedicated, and self-managed instances pointed at GitLab-hosted gateways were already remediated and need no customer action.
- [7]
The flaw was reported via HackerOne by researcher invisiblemeerkat.
- [8]
No public PoC and no known in-the-wild exploitation (CISA: none, as of October 2). No workaround exists.
- [9]
The AI Gateway is the proxy every GitLab AI request passes through, including code suggestions, chat, and Duo Agent Platform flows.
- [10]
A self-hosted gateway holds JWT signing keys for GitLab-to-gateway communication and maintains connections to both the internal GitLab instance and the organization's model providers.
- [11]
Eight months earlier, in February 2026, GitLab patched CVE-2026-1868 in the AI Gateway (Duo Workflow Service): CVSS 9.9, the same vector AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, CWE-1336, via a crafted Duo Agent Platform flow definition, with impact of DoS or code execution on the gateway.
ReportedSupportedSource: dev.to analysis, cross-checked against GitLab's Feb 6 release postView cited source - [12]
CVE-2026-1868 was fixed in AI Gateway 18.6.2, 18.7.1 and 18.8.1, in GitLab's February 6, 2026 AI Gateway patch release.
- [13]
GitLab's February advisory described "insecure template expansion of user supplied data via crafted Duo Agent Platform Flow definitions."
- [14]
GitLab's October advisory describes escaping "the prompt template sandbox via a specially crafted flow configuration."
- [15]
The October advisory does not mention the February flaw.
- [16]
The injection fires in the template engine before any LLM is invoked; it is a server-side code-execution path, not an AI prompt-injection attack.
- [17]
Secondary technical write-ups (aiweekly, forkast, aiunderstanding) identify the engine as using Jinja2-style placeholders; the official advisory only says "prompt template sandbox" and CWE-1336.
- [18]
A public third-party PoC verification report traces CVE-2026-1868 to ai_gateway/prompts/base.py and shows the February fix introduced a PromptSandboxedEnvironment to replace the weaker sandbox.
- [19]
GitLab did targeted outreach to self-hosted gateway customers before the public advisory.
- [20]
All three builds that carried the February CVE-2026-1868 fix (18.6.2, 18.7.1, 18.8.1) fall inside the October CVE-2026-90970 affected range of 18.1.6 through 19.2.3, so a gateway patched in February remains vulnerable to the October flaw.
Sources
1 independent publisher whose own reporting we read for this story.
- dev.toGitLab AI Gateway CVE-2026-90970: "SSTI Wearing an AI Costume"
1 article · October 8, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.