ALEXKRI.NET
Resume Contact
← Back

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

“Prompt template escape” is an RCE class now, and that’s the part worth sitting with. CVE-2026-90970 (CVSS 9.9) lets any logged-in user with Duo Agent Platform access craft a custom flow that breaks out of the prompt sandbox and runs commands on a self-hosted GitLab AI Gateway - the box holding JWT signing keys and your model provider creds. Fixed in 19.2.4, 19.3.2 and 19.4.1. GitLab.com is patched; self-hosted is on you.

Read the source ↗