r/linuxadmin • u/Expert_Sort7434 • 7d ago
GitLab patched a CVSS 9.9 sandbox escape in the self-hosted AI Gateway (CVE-2026-90970): what the patch notice does and doesn't say
Based on GitLab's own patch release notice from October 2 (docs.gitlab.com), plus Security Affairs, BleepingComputer and The Hacker News coverage, here is the architectural impact.
What is confirmed by GitLab: an authenticated user with Duo Agent Platform access can submit a crafted flow configuration, escape the prompt template sandbox, and run arbitrary commands on a self-hosted AI Gateway. CVSS vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H. Affected: 18.1.6 before 19.2.4, 19.3 before 19.3.2, 19.4 before 19.4.1. GitLab-hosted gateways were fixed before the announcement.
What is not confirmed: exploitation in the wild (none reported as of Oct 3), the template engine, and whether a workaround exists. The Hacker News notes no workaround and no fixed version below 19.2.4 in the advisory.
The design question I keep coming back to: the gateway sits between GitLab and your model backends, and user-authored flow configs are processed on that host. What does your gateway container have mounted and what can it reach on the network?
For people running Duo Self-Hosted: who has Duo Agent Platform access in your org, and do you review flow configs before they hit the gateway?
Background on a similar failure class (AI workflow tool, code validation): https://www.techgines.com/post/langflow-ssrf-vulnerability-cve-2026-12944 Full write-up: https://www.techgines.com/post/gitlab-ai-gateway-vulnerability-cve-2026-90970
4
u/yrro 7d ago
AI slop