← All posts / Meta

A Perfect 9.9 for the Prompt Sandbox: GitLab's AI Gateway Flaw Turns Custom Flows into Root Shells

CVE-2026-90970 lets any authenticated Duo Agent Platform user escape GitLab's prompt-template sandbox via a crafted custom flow and run arbitrary commands on self-hosted AI Gateways. Here is what shipped, who is exposed, and why this CWE-1336 class keeps coming back.

A Perfect 9.9 for the Prompt Sandbox: GitLab's AI Gateway Flaw Turns Custom Flows into Root Shells

On October 2, 2026, GitLab published a patch advisory that should end up in every security team’s post-mortem folder. A vulnerability in the GitLab AI Gateway — the service that sits between a GitLab instance and its AI models — earned a CVSS score of 9.9 out of 10, one tick shy of a perfect 10. Tracked as CVE-2026-90970, the flaw allows an authenticated user with Duo Agent Platform access to escape the prompt-template sandbox through a specially crafted flow configuration and execute arbitrary commands on the gateway itself.

What Happened

The AI Gateway is the connective tissue of GitLab’s AI stack. It brokers requests from GitLab to language models, enforces policy, and — in its self-hosted form — exists so that security-conscious organizations can keep AI requests and responses entirely inside their own environment. That last detail is what makes this vulnerability sting: the component marketed as the privacy-preserving option is the one that got the near-perfect score.

The attack surface is the Duo Agent Platform’s custom flows. A custom flow is an AI-powered workflow that users build to automate multi-step tasks — think chained prompts, tool calls, and conditional logic, assembled through configuration rather than code. The bug, which GitLab classifies as an improper neutralization issue in the custom-flow prompt template, means that a maliciously constructed flow configuration can break out of the template sandbox that is supposed to constrain it.

Once out, the attacker lands on the gateway with the ability to run arbitrary commands. And a self-hosted AI Gateway is a juicy landing zone: it holds the signing keys for JSON Web Tokens, which GitLab’s own install documentation says must be treated as sensitive credentials. It also maintains connections both to the GitLab instance and to the organization’s AI model providers. Compromise the gateway and you potentially compromise the trust chain in both directions.

The Blast Radius Is Narrower Than the Score Suggests — and Wider Than It Looks

Two important scoping facts temper the panic. First, only self-hosted AI Gateway deployments are affected. GitLab runs AI Gateways for its customers and had already fixed them before publishing the advisory, so GitLab.com, GitLab Dedicated, and self-managed instances using a GitLab-hosted gateway are protected and need to do nothing. Second, the flaw requires authentication — an account with Duo Agent Platform access, not an anonymous internet stranger.

But the score of 9.9 is not theater, and the reasons are worth sitting with. The CVSS vector is AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H: network-exploitable, low attack complexity, low privileges required, no user interaction, and — critically — a scope change. The S:C means the exploit breaks out of the vulnerable component’s security context into something bigger. High impact across confidentiality, integrity, and availability completes the picture. A low-privileged but authenticated user, with no interaction from a victim, pivoting from a workflow configuration file to command execution on infrastructure that holds JWT signing keys: that is precisely the scenario CVSS was designed to score brutally.

The affected version range is unusually broad. Every AI Gateway release from 18.1.6 onward is in scope — the fix ships in 19.2.4, 19.3.2, and 19.4.1, and no fixed version exists below 19.2.4. That leaves the entire 18.x line and the 19.1 line stranded inside the affected range. GitLab’s maintenance policy lists 19.4, 19.3, and 19.2 as the releases receiving security fixes, which are exactly the three lines that got the patch. Whether older lines will receive backports is not addressed in the advisory.

Déjà Vu: This Is the Second One This Year

If the mechanism sounds familiar, it should. In February 2026, GitLab fixed CVE-2026-1868 — also rated 9.9, also reachable through a crafted flow definition, and also capable of denial of service or code execution on the gateway. Both flaws are template engine weaknesses of the same class: CWE-1336, “Improper Neutralization of Special Elements Used in a Template Engine.”

This is the part of the story that matters most for engineering teams. Template injection is an old, well-understood vulnerability class — it has been ruining server-side renderers since the early 2010s — but it is arriving in AI stacks with a fresh coat of paint. When a prompt template is treated as trusted configuration rather than as the input channel of a Turing-complete engine, every prompt becomes a potential injection vector and every “flow configuration” becomes a potential exploit payload. The sandbox is supposed to be the answer; CVE-2026-90970 demonstrates that the sandbox itself can be the bug.

The credit goes to a HackerOne researcher going by invisiblemeerkat, who responsibly disclosed the issue. As of the disclosure date, CISA’s assessment attached to the CVE record listed exploitation as “none,” and the advisory does not indicate whether the flaw was used in any attacks. There is no public proof of concept yet, but a 9.9 with public patch hashes and detailed version arithmetic is a standing invitation — patch windows are measured in hours, not weeks.

What Self-Hosters Should Actually Do

The remediation is mechanical but has edges. The AI Gateway ships as its own Docker image or Helm chart with its own update path, separate from the main GitLab instance. For Docker deployments: stop and remove the running container, pull and run the new image tag (for example, self-hosted-v19.4.1-ee), and verify the gateway comes back healthy. Helm deployments set the new tag in the chart’s image setting.

The awkward questions are the ones the advisory does not answer. GitLab’s install guide tells administrators to use the gateway image that matches their GitLab minor version — but the advisory does not say whether a 19.2.4 gateway is compatible with a GitLab 19.1 or earlier instance, nor whether fixes for the older lines are planned. No workaround exists for gateways that cannot be updated yet, and there is no documented method to check whether a gateway was attacked before it was patched. Teams running the 18.x gateway line may be facing an unplanned platform upgrade rather than a simple tag bump.

Given what the gateway holds, the conservative playbook after patching is straightforward: rotate the JWT signing keys, audit the gateway’s outbound connections to model providers, and review custom flow configurations for anything that appeared without a corresponding change ticket. A prompt-template sandbox escape is, in the end, an arbitrary-code-execution primitive — treat the post-patch environment as potentially touched until proven otherwise.

The Pattern Behind the Patch

Zoom out and CVE-2026-90970 fits neatly into 2026’s dominant security narrative: the AI infrastructure layer is accumulating the same vulnerability classes that web infrastructure spent a decade eradicating, but at machine speed. AWS’s Loom agent control plane got its CVSS 10.0 this week. Apple is tightening macOS Full Disk Access explicitly because AI agents wandered into private messages. And GitLab — a company whose entire pitch to enterprises is disciplined, auditable software delivery — shipped two 9.9 template-injection bugs in its AI plumbing in eight months.

None of this argues against AI features. It argues that AI features are infrastructure now, and infrastructure gets exploited with off-the-shelf techniques that predate the technology they now target. The prompt template is a template engine. The flow configuration is input. The sandbox is a boundary. Every lesson from a decade of server-side template injection applies verbatim — the only new thing is how quickly the industry had to relearn them.

Self-hosted AI Gateway operators should treat this as a same-day patch. Everyone else should note the pattern: the most dangerous bugs in AI stacks are not exotic attacks on model weights. They are the classics, wearing a new name badge that says “prompt.”