A server-side template injection in GitLab AI Gateway lets an authenticated user break out of the prompt-template sandbox and execute arbitrary commands on the gateway host, shattered.io reported, citing GitLab's own advisory along with coverage from The Hacker News and SecurityAffairs1. The vulnerability, tracked as CVE-2026-90970, carries a CVSS score of 9.9 out of 10. GitLab disclosed the flaw on October 2, 2026.
What the bug does
GitLab AI Gateway is the compute layer that powers GitLab Duo, the company's AI coding assistant and agent suite, according to shattered.io. It runs on self-hosted GitLab instances and brokers the prompt flows feeding GitLab's large-language-model integrations. A user with access to GitLab Duo Agent Platform can submit a specially crafted flow configuration that the template engine fails to sanitize, escaping the sandbox and reaching the underlying operating system, the report said.
The flaw is classified as improper neutralization of special elements in a template engine, per the CVE record and GitHub Advisory Database, which track it under GHSA-5295-vp56-jghq. The attacker needs valid credentials and GitLab Duo Agent Platform permissions to exploit it.
Affected versions and fix
Three affected ranges exist inside the AI Gateway release line, according to shattered.io: versions 18.1.6 up to but not including 19.2.4, the 19.3.x line before 19.3.2, and the 19.4.x line before 19.4.1. GitLab's remediation path is to upgrade to 19.2.4, 19.3.2, or 19.4.1 depending on the branch. GitLab shipped fixes within days of disclosure, the report said.
GitLab's hosted service, GitLab.com, is not described as affected in the available reporting. GitLab's advisory credits the fix to its own security team without naming an external finder.
No exploitation observed
As of shattered.io's reporting, no evidence points to in-the-wild exploitation of CVE-2026-90970. No proof-of-concept exploit code has been published. The flaw has not appeared on the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog, the report said. Rapid7's vulnerability database logged the issue on the same day GitLab's advisory went public, and the National Vulnerability Database entry was updated on October 3.
ANALYSIS The near-maximum severity score reflects the scope of what a successful exploit grants: full command execution on the host that mediates every AI-assisted code suggestion and automated flow for a self-hosted GitLab instance. The authentication requirement narrows the attack surface but does not eliminate it, since exploitation requires only standard platform-level permissions rather than administrator access.