GitLab Patches Critical Vulnerability in AI Gateway
GitLab has released security updates for a critical vulnerability in its Self-Hosted AI Gateway, a component used with the company's AI-powered development tools.
The vulnerability, tracked as CVE-2026-90970, has been assigned a CVSS severity score of 9.9 out of 10, placing it in the critical category.
The flaw could allow an authenticated user with access to the GitLab Duo Agent Platform to escape a security boundary in the AI Gateway and execute arbitrary commands on the underlying server under certain conditions.
What Is the GitLab AI Gateway?
GitLab's AI Gateway provides infrastructure for AI capabilities used by the company's Duo Agent Platform.
The platform allows software-development teams to use AI agents for tasks such as coding, security analysis, vulnerability remediation and software delivery workflows.
GitLab has increasingly expanded its agentic AI capabilities, allowing AI systems to interact with code repositories, pipelines and security information.
The AI Gateway can therefore become an important security boundary between AI-powered workflows and the underlying computing environment.
How the Vulnerability Works
The vulnerability is related to the way the AI Gateway handles prompt templates and flow configurations.
A malicious or compromised authenticated user with the necessary Duo Agent Platform access could potentially manipulate a flow configuration in a way that escapes the intended prompt-template sandbox.
Under vulnerable configurations, this could result in arbitrary command execution on the AI Gateway server.
The issue is particularly significant for organizations running their own AI Gateway infrastructure because successful exploitation could potentially affect the server hosting the service.
Who Is Affected?
The vulnerability affects certain versions of GitLab's self-hosted AI Gateway.
Organizations using affected versions should review their deployments and apply the security updates released by GitLab.
The issue is not simply a general vulnerability affecting every GitLab installation. Its relevance is specifically connected to deployments using the affected AI Gateway functionality.
GitLab Releases Security Updates
GitLab released updated versions to address the vulnerability.
The patched releases include 19.2.4, 19.3.2 and 19.4.1, according to security reporting on the issue.
Organizations running vulnerable versions are advised to upgrade to an appropriate fixed release rather than relying on the affected versions.
GitLab's security documentation recommends customers keep supported installations updated and says the company can issue additional security releases when critical vulnerabilities require urgent action.
Why the Vulnerability Matters in the AI Era
The vulnerability highlights a broader cybersecurity challenge created by the rapid adoption of AI agents in software development.
AI agents are increasingly being given access to code repositories, development environments, command-line tools and other systems.
These capabilities can significantly increase automation, but they also create additional security boundaries that must be protected.
If an AI-related service contains a vulnerability that allows access to the underlying system, attackers could potentially use the service as a route toward other resources.
AI Agents Need Stronger Security Controls
GitLab has been expanding its agentic AI platform throughout 2026.
The company has introduced capabilities that allow AI agents to help developers review code, configure pipelines and identify or remediate security vulnerabilities.
GitLab has also been developing governance features designed to provide organizations with identity controls, policies, auditing and approval mechanisms for AI-agent actions.
The latest vulnerability demonstrates why these controls are becoming increasingly important as AI systems receive access to more parts of the software-development lifecycle.
The Difference Between AI and Traditional Software Security
Traditional software vulnerabilities can affect databases, web applications, operating systems and APIs.
AI-enabled systems introduce additional layers, including prompts, model interactions, tool calls, agent workflows and automated actions.
This means security teams increasingly have to consider not only whether an application contains a conventional software vulnerability, but also how AI agents interact with the surrounding infrastructure.
A vulnerability in an AI Gateway can therefore have implications beyond the AI model itself.
Organizations Should Review Their AI Infrastructure
Companies using self-hosted AI systems should maintain an inventory of AI services and the infrastructure supporting them.
Security teams should also review authentication, access permissions, network exposure and logging for AI-related services.
Keeping AI infrastructure updated is particularly important because these systems can have access to sensitive source code, credentials and development environments.
Organizations should follow the vendor's security guidance and apply the appropriate patches rather than attempting to develop unofficial fixes for a critical vulnerability.
AI Security Is Becoming a Major Enterprise Issue
The GitLab incident arrives during a period of rapid growth in enterprise AI adoption.
Companies are deploying AI agents to automate software development, customer support, research, cybersecurity and other business processes.
As these systems become more autonomous, they increasingly require access to tools and data that were previously controlled by human users.
That creates a new security challenge: organizations must balance the productivity benefits of AI automation with strict controls over what agents and AI infrastructure are allowed to access.
What Happens Next?
Organizations using affected GitLab AI Gateway versions will need to update their deployments and review their security configurations.
Security researchers are likely to continue examining AI infrastructure for vulnerabilities as more companies deploy agentic systems in production environments.
The GitLab vulnerability also demonstrates why AI security cannot be separated from traditional application and infrastructure security.
As AI agents gain the ability to interact with real software systems, protecting the infrastructure around those agents becomes just as important as securing the AI models themselves.
A Warning for the Growing AI Agent Industry
The critical GitLab vulnerability is another example of the security challenges emerging alongside the rapid expansion of AI-powered software development.
AI Gateway systems are designed to connect intelligent software agents with real development environments, making them valuable components of modern software workflows.
At the same time, that connectivity means vulnerabilities can have consequences beyond the AI interface.
With CVE-2026-90970 receiving a 9.9 critical severity rating and patches already available, organizations using affected self-hosted AI Gateway versions should treat software updates and access controls as an important part of their AI security strategy.
Journalist: Vijay Singh