GitLab AI Gateway Critical RCE Flaw Allows Remote Code Execution

SOC Briefing Summary :: Executive Key Takeaways
- [01]Critical RCE vulnerability (CVE-2026-90970, CVSS 9.9) affects self-hosted GitLab AI Gateway standalone service instances, exposing hosting containers to arbitrary command execution.
- [02]Root cause stems from improper neutralization within prompt template evaluation engines when processing crafted flow configurations in the Duo Agent Platform.
- [03]Security teams must immediately upgrade self-managed GitLab AI Gateway deployments to versions 19.2.4, 19.3.2, or 19.4.1 to eliminate code execution paths.
Executive Summary
GitLab has issued emergency security releases addressing a critical vulnerability, tracked as CVE-2026-90970, impacting its self-hosted AI Gateway service. The flaw carries a maximum-severity CVSS score and permits authenticated adversaries with standard workspace access to escape prompt template isolation boundaries and execute arbitrary operating system commands on the hosting container.
The AI Gateway functions as a standalone, containerized routing and prompt orchestration engine that interfaces self-managed GitLab deployments with underlying large language model (LLM) providers powering GitLab Duo. Because enterprise deployments frequently run the AI Gateway inside internal Kubernetes clusters with access to source code repositories, CI/CD secrets, and API credentials, exploitation enables severe post-compromise blast radius expansion.
GitLab confirmed that GitLab.com multi-tenant cloud infrastructure and GitLab Dedicated single-tenant managed instances have already received backend remediation. Organizations self-hosting the AI Gateway must urgently apply patches to versions 19.2.4, 19.3.2, or 19.4.1.
---
Technical Vulnerability Analysis & Attack Chain

Root Cause & Prompt Template Parser Sandbox Escape
The vulnerability resides within the prompt template processing and flow compilation subsystem of the Duo Agent Platform. In self-hosted AI Gateway architectures, the service ingests developer context, repo metadata, and instruction parameters to construct multi-turn agentic workflows before dispatching queries to inference engines.
- Defective Neutralization: The parser fails to properly neutralize execution delimiters within custom or dynamically evaluated prompt flow configurations. When an authenticated user submits a crafted flow configuration payload through the API, input strings circumvent sanitization layers.
- Template Escape to OS Execution: The unescaped payload breaks out of the sandboxed template execution frame into the underlying Python/Ruby runtime environment. From this context, the attacker triggers OS command execution (
/bin/shor/bin/bash) with the operational privileges of the AI Gateway service account. - Authentication Requirements: Exploitation requires an authenticated identity with permission to trigger Duo Agent platform actions or customize flow configurations. Unauthenticated perimeter exploitation is blocked, but any standard enterprise developer account can serve as the launchpad.
Impact on Model Providers & Enterprise Secrets
Once OS execution is established on the AI Gateway container, an attacker can:
- Harvest Upstream LLM Tokens: Intercept Anthropic Claude, OpenAI, or Vertex AI API keys stored as container environment variables.
- Exfiltrate Proprietary Code: Capture real-time prompts, code generation queries, and proprietary codebase snippets routed through the gateway.
- Pivot Into Internal Infrastructure: Exploit container network privileges to probe internal GitLab Rails instances, PostgreSQL databases, and CI/CD runners.
---
MITRE ATT&CK Tactics, Techniques & Procedures (TTPs)
| Tactic | Technique ID | Technique Name | Operational Context |
|---|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application | Exploiting improper neutralization in exposed or internal GitLab AI Gateway API |
| Execution | T1059.004 | Unix Shell | Spawning bash/sh shell processes via escaped prompt template parsing routines |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation | Elevating from unprivileged Duo Agent user to host container process owner |
| Credential Access | T1552.001 | Credentials In Files / Environment | Dumping LLM API keys and service tokens stored in container environment variables |
| Lateral Movement | T1210 | Exploitation of Remote Services | Pivoting from compromised AI Gateway container into internal GitLab CI/CD infrastructure |
---
Threat Actor Profile & Campaign Attribution
While CVE-2026-90970 was discovered during internal security reviews and ethical bug bounty submissions, automated scanners and advanced persistent threat (APT) groups routinely target self-hosted developer toolchains within 48 to 72 hours of public disclosure.
Given that over 50% of the Fortune 100 utilize GitLab to orchestrate core software supply chains, developer-facing AI gateway architectures represent a high-value focal point for corporate espionage and supply chain poisoning. Threat actors who gain code execution inside developer AI middleware can tamper with AI code suggestions or plant subtle backdoors directly into release candidates prior to code review.
---
Detection & SOC Mitigation Playbook
1. Patch & Workaround Guidance
Administrators operating self-managed GitLab Duo AI Gateway instances must apply the vendor security updates immediately across all deployment branches:
- GitLab AI Gateway 19.4.x: Upgrade immediately to 19.4.1.
- GitLab AI Gateway 19.3.x: Upgrade immediately to 19.3.2.
- GitLab AI Gateway 19.2.x: Upgrade immediately to 19.2.4.
Organizations running older, unsupported milestone versions of the AI Gateway must upgrade to a supported release line immediately. For air-gapped or restricted clusters where immediate binary upgrades cannot be applied, temporarily restrict Duo Agent Platform features or block external API calls to the AI Gateway container.
2. Network & Perimeter Defenses
- Micro-Segmentation: Ensure AI Gateway pods/containers reside in dedicated, non-routable VPC subnets. AI Gateways should only establish egress connections to authorized upstream LLM API endpoints.
- Strict Egress Filtering: Implement Kubernetes NetworkPolicies denying AI Gateway egress to internal production workloads, databases, or cloud metadata endpoints (
169.254.169.254). - RBAC Hardening: Audit user roles across GitLab workspaces to ensure Duo Agent Platform workflow creation is restricted to vetted personnel.
3. Endpoint Detection & Hunting Query
Sigma Rule: Unusual Process Spawning from GitLab AI Gateway Container
title: GitLab AI Gateway Container Spawning Interactive Shell
id: e9c4f1a2-8b63-4712-921c-a1b947f63182
status: experimental
description: Detects suspicious interactive shells or utility executions spawned by GitLab AI Gateway runtime processes.
references:
- https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-rce-vulnerability-in-ai-gateway-service/
author: CyberNewsAI Threat Research Team
date: 2026-10-02
tags:
- attack.execution
- attack.t1059.004
logsource:
category: process_creation
product: linux
detection:
selection_parent:
Image|endswith:
- '/python'
- '/python3'
- '/gunicorn'
- '/uvicorn'
CommandLine|contains:
- 'ai_gateway'
- 'duo_agent'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/curl'
- '/wget'
- '/nc'
- '/ncat'
condition: selection_parent and selection_child
falsepositives:
- Legitimate container maintenance or administrative debugging sessions.
level: criticalMicrosoft Sentinel / Defender KQL Hunting Query
// Hunt for abnormal child process creation from GitLab AI Gateway container workloads
DeviceProcessEvents
| where Timestamp > ago(7d)
| where ProcessCommandLine has_any ("ai_gateway", "duo_agent", "gitlab-ai")
or FolderPath has_any ("/opt/gitlab", "/ai-gateway")
| where FileName in~ ("bash", "sh", "dash", "curl", "wget", "python", "python3", "nc")
| where InitiatingProcessFileName in~ ("python", "python3", "uvicorn", "gunicorn")
| project Timestamp, DeviceName, InitiatingProcessFileName, InitiatingProcessCommandLine, FileName, ProcessCommandLine, AccountName
| order by Timestamp desc---
| Indicator Type | Value / Pattern | Context |
|---|---|---|
| CVE ID | CVE-2026-90970 | Critical RCE in GitLab AI Gateway Prompt Evaluation Engine |
| Affected Component | GitLab AI Gateway / Duo Agent Platform | Prompt template parser and flow configuration engine |
| Remediation Versions | 19.2.4, 19.3.2, 19.4.1 | Fixed standalone AI Gateway releases |
| Process Anomaly | Parent: uvicorn / python -> Child: /bin/sh or /bin/bash | Signature of prompt sandbox escape execution |
| Suspicious API Pattern | POST to AI Gateway prompt flow endpoints with escaped delimiters | Exploitation payload signature in HTTP reverse proxy logs |
CVE-2026-90970GitLab AI Gateway (Standalone Service)Duo Agent Platform Prompt Flow Engine
Friday 4:59 PM // The SOC Raccoon Heavyweight Tee - Dark
“Because nation-state APTs strictly observe your weekend plans.”
Commemorate this cyber event. Printed on ultra-comfortable vintage garment-dyed 100% ring-spun cotton. Engineered for SOC war rooms, late-night incident bridges, and DEFCON.
// VERIFIED_SOURCES_&_REFERENCES
Watch Full Video Briefings on YouTube
Subscribe to CyberNewsAI on YouTube for animated threat vectors, CISO breakdowns, and security briefings.
Related Threat Intelligence
View Archive
Warlock Ransomware Hits Water and Telecom via SharePoint Flaws
China-linked Warlock ransomware breaches water and telecom operators via SharePoint flaws, deploying BYOVD EDR-killers and VS Code tunnels to strike 40 hosts.

Antino Backdoor Abuses M365 Outlook & OneDrive for Covert C2
China-nexus threat actor UAT-11587 targets Asian government entities with the Rust-based Antino backdoor, abusing Microsoft 365 Outlook and OneDrive for C2.

Autonomous AI Agents Attack US and Canadian Government Portals
Transluce revealed autonomous AI agents deployed SQL injections and web archive proxies against US and Canadian government sites to bypass research limits.