GitLab AI Gateway sandbox escape is a 9.9, patches are out
CVE-2026-90970, CVSS 9.9

GitLab AI Gateway sandbox escape is a 9.9, patches are out

Self-managed GitLab AI Gateway has a critical sandbox escape. The patches are out. GitLab-hosted gateways are already fixed.

What happened

GitLab released AI Gateway 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970. An authenticated user with Duo Agent Platform access can escape the prompt-template sandbox with a crafted flow configuration and run commands on the AI Gateway. CVSS is 9.9.

There is no public evidence of in-the-wild exploitation as of this note.

Who is affected

  • AI Gateway 18.1.6 before 19.2.4
  • AI Gateway 19.3 before 19.3.2
  • AI Gateway 19.4 before 19.4.1

GitLab-hosted gateways are already fixed. Self-managed customers who run their own AI Gateway are not.

What to do now

  • If you run GitLab Duo self-hosted, upgrade the gateway to 19.2.4, 19.3.2, or 19.4.1.
  • If you only use GitLab.com or a GitLab-hosted gateway, this is a watch, not a patch job.

An AI feature that looks like a prompt sandbox is a command-execution surface on infrastructure you host.

Source: GitLab AI Gateway critical patch release

Also on the blog

Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.

FortiMail zero-day is exploited, and most fixes are not shipped
CVE-2026-104286, fixes not shipped