A logged-in user with Duo Agent Platform access could escape the prompt template sandbox and run commands on the gateway.
The Hacker News reports that GitLab has patched a critical flaw, tracked as CVE-2026-90970 with a CVSS score of 9.9, in its AI Gateway, the service that connects a GitLab instance to AI models. A logged-in user with Duo Agent Platform access could escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the gateway. Only organizations that host their own AI Gateway need to act; GitLab.com, GitLab Dedicated, and self-managed instances that use a GitLab-hosted gateway do not, since GitLab has already fixed those.
Fixed versions are Gateway 18.1.6 and later, 19.2.4, 19.3.2 and 19.4.1. CISA added an assessment to the CVE record on October 2 listing exploitation status as "none."
Why it matters: as enterprises wire AI gateways directly into developer workflows, a sandbox escape in that gateway hands an authenticated user a path to command execution on infrastructure that touches code, credentials and cloud resources alike. Self-hosted AI Gateway operators should patch now and review who holds Duo Agent Platform access.