Skip to main content

GitLab warns of critical AI Gateway command-execution flaw

3 OCTOBER 2026·2 MIN READ·3 SOURCES

GitLab disclosed a critical vulnerability in its AI Gateway that could allow arbitrary command execution on the service. The company urges customers running affected self-hosted gateways to upgrade; GitLab-hosted gateways have already been fixed.

GitLab warns of critical AI Gateway command-execution flaw

Key takeaways · 4

  • 01

    Check whether a self-hosted AI Gateway falls within the affected version ranges: 18.1.6 to before 19.2.4, 19.3 before 19.3.2, or 19.4 before 19.4.1.

  • 02

    Upgrade affected self-hosted gateways to 19.2.4, 19.3.2, or 19.4.1, as applicable; GitLab recommends upgrading as soon as possible.

  • 03

    Customers using GitLab.com, GitLab Dedicated, or self-managed instances with a GitLab-hosted AI Gateway are protected and need take no action.

  • 04

    The advisory does not say whether attacks have occurred, and it gives no method for checking whether a gateway was attacked before an update.

How the flaw works

GitLab disclosed CVE-2026-90970 on October 2 and rated the AI Gateway vulnerability critical, with a CVSS score of 9.9 out of 10.[1] The flaw could allow arbitrary command execution on the AI Gateway.[2] GitLab describes the issue as improper neutralization in a custom flow prompt template; the attack involves escaping the prompt-template sandbox with a specially crafted flow configuration.[2] AI Gateway connects a GitLab instance to AI models and provides access to AI-native GitLab Duo features.[3][1]

Which installations need an update

The affected versions are AI Gateway 18.1.6 up to, but not including, 19.2.4; 19.3 versions before 19.3.2; and 19.4 versions before 19.4.1.[2] GitLab released versions 19.2.4, 19.3.2, and 19.4.1 as fixes.[2] The company strongly recommends that customers with affected self-hosted installations upgrade as soon as possible.[2] GitLab contacted customers running self-hosted AI Gateways before publishing its release guidance.[2] The Hacker News reports that only organizations hosting their own AI Gateway need to act.[1]

What is and is not confirmed

GitLab says its GitLab-hosted AI Gateways have already been fixed.[2] Customers using GitLab.com, GitLab Dedicated, or self-managed instances with a GitLab-hosted AI Gateway are protected and need take no action.[2] The advisory does not state whether the vulnerability has been used in attacks; CISA’s assessment on the CVE record listed exploitation as “none.”[1] That assessment is not confirmation that no attack occurred. The Hacker News reports that the advisory lists no workaround for gateways that cannot yet be updated, and that it gives no method for checking whether a gateway was attacked before it was updated.[1]

For teams that operate their own AI Gateway, the key decision is whether their installed version falls within the affected ranges and can be moved to a fixed release. Teams using GitLab-hosted gateways are in a different position: GitLab says those gateways are fixed and customers need take no action.

Why it matters
Story quiz

Test yourself on this story — 1 question.

Create a free account to take the quiz, earn XP, and get a daily session built for your industry.

Take the quiz

How this developed

  1. 3 October 2026

    GitLab warns of critical AI Gateway command-execution flaw

Sources

AI fluency, one session a day, built for your work.