GitLab AI Gateway Critical RCE Flaw Allows Remote Code Execution

•By CyberNewsAI Admin•VERIFIED INTEL
GitLab AI Gateway Critical RCE Vulnerability CVE-2026-90970 Architecture and Telemetry Overview

SOC Briefing Summary :: Executive Key Takeaways

  • [01]Critical RCE vulnerability (CVE-2026-90970, CVSS 9.9) affects self-hosted GitLab AI Gateway standalone service instances, exposing hosting containers to arbitrary command execution.
  • [02]Root cause stems from improper neutralization within prompt template evaluation engines when processing crafted flow configurations in the Duo Agent Platform.
  • [03]Security teams must immediately upgrade self-managed GitLab AI Gateway deployments to versions 19.2.4, 19.3.2, or 19.4.1 to eliminate code execution paths.
SHARE INTEL:Reddit

Executive Summary

GitLab has issued emergency security releases addressing a critical vulnerability, tracked as CVE-2026-90970, impacting its self-hosted AI Gateway service. The flaw carries a maximum-severity CVSS score and permits authenticated adversaries with standard workspace access to escape prompt template isolation boundaries and execute arbitrary operating system commands on the hosting container.

The AI Gateway functions as a standalone, containerized routing and prompt orchestration engine that interfaces self-managed GitLab deployments with underlying large language model (LLM) providers powering GitLab Duo. Because enterprise deployments frequently run the AI Gateway inside internal Kubernetes clusters with access to source code repositories, CI/CD secrets, and API credentials, exploitation enables severe post-compromise blast radius expansion.

GitLab confirmed that GitLab.com multi-tenant cloud infrastructure and GitLab Dedicated single-tenant managed instances have already received backend remediation. Organizations self-hosting the AI Gateway must urgently apply patches to versions 19.2.4, 19.3.2, or 19.4.1.

---

Technical Vulnerability Analysis & Attack Chain

Attack Chain Flow
// Attack Chain Flow

Root Cause & Prompt Template Parser Sandbox Escape

The vulnerability resides within the prompt template processing and flow compilation subsystem of the Duo Agent Platform. In self-hosted AI Gateway architectures, the service ingests developer context, repo metadata, and instruction parameters to construct multi-turn agentic workflows before dispatching queries to inference engines.

  • Defective Neutralization: The parser fails to properly neutralize execution delimiters within custom or dynamically evaluated prompt flow configurations. When an authenticated user submits a crafted flow configuration payload through the API, input strings circumvent sanitization layers.
  • Template Escape to OS Execution: The unescaped payload breaks out of the sandboxed template execution frame into the underlying Python/Ruby runtime environment. From this context, the attacker triggers OS command execution (/bin/sh or /bin/bash) with the operational privileges of the AI Gateway service account.
  • Authentication Requirements: Exploitation requires an authenticated identity with permission to trigger Duo Agent platform actions or customize flow configurations. Unauthenticated perimeter exploitation is blocked, but any standard enterprise developer account can serve as the launchpad.

Impact on Model Providers & Enterprise Secrets

Once OS execution is established on the AI Gateway container, an attacker can:

  1. Harvest Upstream LLM Tokens: Intercept Anthropic Claude, OpenAI, or Vertex AI API keys stored as container environment variables.
  2. Exfiltrate Proprietary Code: Capture real-time prompts, code generation queries, and proprietary codebase snippets routed through the gateway.
  3. Pivot Into Internal Infrastructure: Exploit container network privileges to probe internal GitLab Rails instances, PostgreSQL databases, and CI/CD runners.

---

MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)

MITRE ATT&CK • OPERATIONAL TTP MAPPING
TacticTechnique IDTechnique NameOperational Context
Initial AccessT1190Exploit Public-Facing ApplicationExploiting improper neutralization in exposed or internal GitLab AI Gateway API
ExecutionT1059.004Unix ShellSpawning bash/sh shell processes via escaped prompt template parsing routines
Privilege EscalationT1068Exploitation for Privilege EscalationElevating from unprivileged Duo Agent user to host container process owner
Credential AccessT1552.001Credentials In Files / EnvironmentDumping LLM API keys and service tokens stored in container environment variables
Lateral MovementT1210Exploitation of Remote ServicesPivoting from compromised AI Gateway container into internal GitLab CI/CD infrastructure

---

Threat Actor Profile & Campaign Attribution

While CVE-2026-90970 was discovered during internal security reviews and ethical bug bounty submissions, automated scanners and advanced persistent threat (APT) groups routinely target self-hosted developer toolchains within 48 to 72 hours of public disclosure.

Given that over 50% of the Fortune 100 utilize GitLab to orchestrate core software supply chains, developer-facing AI gateway architectures represent a high-value focal point for corporate espionage and supply chain poisoning. Threat actors who gain code execution inside developer AI middleware can tamper with AI code suggestions or plant subtle backdoors directly into release candidates prior to code review.

---

Detection & SOC Mitigation Playbook

1. Patch & Workaround Guidance

Administrators operating self-managed GitLab Duo AI Gateway instances must apply the vendor security updates immediately across all deployment branches:

  • GitLab AI Gateway 19.4.x: Upgrade immediately to 19.4.1.
  • GitLab AI Gateway 19.3.x: Upgrade immediately to 19.3.2.
  • GitLab AI Gateway 19.2.x: Upgrade immediately to 19.2.4.

Organizations running older, unsupported milestone versions of the AI Gateway must upgrade to a supported release line immediately. For air-gapped or restricted clusters where immediate binary upgrades cannot be applied, temporarily restrict Duo Agent Platform features or block external API calls to the AI Gateway container.

2. Network & Perimeter Defenses

  • Micro-Segmentation: Ensure AI Gateway pods/containers reside in dedicated, non-routable VPC subnets. AI Gateways should only establish egress connections to authorized upstream LLM API endpoints.
  • Strict Egress Filtering: Implement Kubernetes NetworkPolicies denying AI Gateway egress to internal production workloads, databases, or cloud metadata endpoints (169.254.169.254).
  • RBAC Hardening: Audit user roles across GitLab workspaces to ensure Duo Agent Platform workflow creation is restricted to vetted personnel.

3. Endpoint Detection & Hunting Query

Sigma Rule: Unusual Process Spawning from GitLab AI Gateway Container

QUERY / DETECTION_RULE
SIGMA / YAML
title: GitLab AI Gateway Container Spawning Interactive Shell
id: e9c4f1a2-8b63-4712-921c-a1b947f63182
status: experimental
description: Detects suspicious interactive shells or utility executions spawned by GitLab AI Gateway runtime processes.
references:
  - https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
  - attack.execution
  - attack.t1059.004
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    Image|endswith:
      - '/python'
      - '/python3'
      - '/gunicorn'
      - '/uvicorn'
    CommandLine|contains:
      - 'ai_gateway'
      - 'duo_agent'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
  condition: selection_parent and selection_child
falsepositives:
  - Legitimate container maintenance or administrative debugging sessions.
level: critical

Microsoft Sentinel / Defender KQL Hunting Query

QUERY / DETECTION_RULE
SENTINEL / KQL
// Hunt for abnormal child process creation from GitLab AI Gateway container workloads
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("ai_gateway", "duo_agent", "gitlab-ai")
    or FolderPath has_any ("/opt/gitlab", "/ai-gateway")
| where FileName in~ ("bash", "sh", "dash", "curl", "wget", "python", "python3", "nc")
| where InitiatingProcessFileName in~ ("python", "python3", "uvicorn", "gunicorn")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName
| order by Timestamp desc

---

Indicator TypeValue / PatternContext
CVE IDCVE-2026-90970Critical RCE in GitLab AI Gateway Prompt Evaluation Engine
Affected ComponentGitLab AI Gateway / Duo Agent PlatformPrompt template parser and flow configuration engine
Remediation Versions19.2.4, 19.3.2, 19.4.1Fixed standalone AI Gateway releases
Process AnomalyParent: uvicorn / python -> Child: /bin/sh or /bin/bashSignature of prompt sandbox escape execution
Suspicious API PatternPOST to AI Gateway prompt flow endpoints with escaped delimitersExploitation payload signature in HTTP reverse proxy logs
Indicators of Compromise (IOCs)
3 Identified
VulnerabilityCVE-2026-90970
ServiceGitLab AI Gateway (Standalone Service)
ComponentDuo Agent Platform Prompt Flow Engine
// EVERGREEN RELIC // P1 INCIDENT
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Dark mockup

Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Dark

“Because nation-state APTs strictly observe your weekend plans.”

Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.

Direct Armory Fulfillment$20
ACQUIRE RELIC
Fast US Shipping (2-4 Days)• 1-Click Apple / Google Pay
SHARE INTEL:Reddit
OPERATIONS_BROADCAST

Watch Full Video Briefings on YouTube

Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.

SUBSCRIBE_ON_YOUTUBE