Self-managed GitLab AI Gateway has a critical sandbox escape. The patches are out. GitLab-hosted gateways are already fixed.
What happened
GitLab released AI Gateway 19.2.4, 19.3.2, and 19.4.1 to fix CVE-2026-90970. An authenticated user with Duo Agent Platform access can escape the prompt-template sandbox with a crafted flow configuration and run commands on the AI Gateway. CVSS is 9.9.
There is no public evidence of in-the-wild exploitation as of this note.
Who is affected
- AI Gateway 18.1.6 before 19.2.4
- AI Gateway 19.3 before 19.3.2
- AI Gateway 19.4 before 19.4.1
GitLab-hosted gateways are already fixed. Self-managed customers who run their own AI Gateway are not.
What to do now
- If you run GitLab Duo self-hosted, upgrade the gateway to 19.2.4, 19.3.2, or 19.4.1.
- If you only use GitLab.com or a GitLab-hosted gateway, this is a watch, not a patch job.
An AI feature that looks like a prompt sandbox is a command-execution surface on infrastructure you host.
Source: GitLab AI Gateway critical patch release
Also on the blog
- Attackers are getting more from AI than defenders
- CISA lists two Zammad bugs that an AI-driven attack already chained to root
Next step: If this is on your network or a client's, ask Matthews Enterprises to check exposure.