AI and data stack advisories

Severe, 6 weeks2973Projects319

2973 severe, 6 weeks · 319 projects

GitLabCVE-2026-90970

GitLab AI Gateway: template injection

GitLab

CVE-2026-90970 · Published Oct 2, 2026

Critical9.9
Fix: upgrade to 19.2.4 or later (3 fixed versions below)
GitLab advisory

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

Affected versions

PackageAffectedFixed in
GitLab AI Gateway
Product
>= 18.1.6, < 19.2.419.2.4
>= 19.3, < 19.3.219.3.2
>= 19.4, < 19.4.119.4.1
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-1336

More GitLab advisories

All GitLab
Advisory
GitLab: missing authorization
Medium4.3Sep 29
GitLab: cross-site scripting
High8.7Sep 29
GitLab: improper authorization
Low3.7Sep 29
GitLab: improper authorization
Medium4.3Sep 29
GitLab: code execution
Critical9.9Sep 24
GitLab: missing authorization
High7.7Sep 24