External risk intelligence

GitLab AI Gateway Prompt Injection Allows Command Execution

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-90970

The GitLab AI Gateway is an intermediary service component often deployed as an API or edge service to facilitate AI feature communication. While it requires authentication, such gateway components are commonly exposed to network or internet segments to support distributed development environments and integrated AI workflows.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

GitLab has addressed a critical vulnerability in its AI Gateway component. This issue could allow an authenticated user to execute arbitrary commands, potentially impacting systems running the AI Gateway. The main concern is to confirm if this specific component is in use within our environment.

  • Authenticated users could run unintended commands.
  • This could affect AI Gateway services.
  • Confirm relevance and exposure.

Attack Path

How an attacker could exploit the issue

An attacker with authenticated access to the GitLab AI Gateway could craft a special flow configuration to break out of the prompt template sandbox. This escape allows for the execution of arbitrary commands on the AI Gateway itself, potentially leading to further compromise.

  • Requires authenticated user with platform access.
  • Triggered by a crafted flow configuration.
  • Risk of arbitrary command execution.

Live Threat

Current exploitation, exposure, and threat context

The GitLab AI Gateway, when configured with specific flow settings, could allow an authenticated user with Duo Agent Platform access to execute arbitrary commands on the AI Gateway. This risk is present when the prompt template sandbox is not properly isolated, enabling the user to bypass intended restrictions.

  • AI Gateway system.
  • Authenticated user crafts flow configuration.
  • Arbitrary command execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The GitLab AI Gateway component is likely managed by platform or infrastructure teams, with potential involvement from application owners and security teams due to its network exposure and critical function. The immediate first step is to identify all instances of the AI Gateway, assess their business criticality and network reachability, and confirm the accountable owner for each instance to prioritize remediation efforts.

  • Platform or infrastructure teams own this.
  • Verify AI Gateway instances and network exposure.
  • Plan and coordinate remediation with owners.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the GitLab AI Gateway?

The GitLab AI Gateway is a specialized service component that facilitates communication between GitLab's platform and various AI models. It acts as an intermediary layer, often deployed as an API or edge service, to handle requests for features like the Duo Agent. It is designed to manage complex AI interactions while shielding the core GitLab application from the technical overhead of processing these dynamic AI workflows.

What does CWE-1336 mean for CVE-2026-90970?

This vulnerability is classified under CWE-1336, which relates to the improper neutralization of special elements used in a template engine. In the context of this CVE, it means the AI Gateway's prompt template sandbox—a security boundary intended to restrict AI actions—was flawed. Because the sandbox failed to properly validate input, a user could manipulate the template to break out of its restricted environment and execute unauthorized commands on the underlying system.

How is this command execution triggered?

An attacker triggers this by providing a specially crafted flow configuration to the AI Gateway. It is important to note that this does not occur through standard user prompts or typical interaction with AI features; it requires specific, non-default configuration inputs. Furthermore, users without Duo Agent Platform access cannot initiate this process, as the vulnerability requires pre-existing authenticated access to those specific AI platform functions.

Why does Halo Surface Signal flag this as external?

Halo Surface Signal identifies this as an external risk because the GitLab AI Gateway often operates as an edge service. To support distributed development teams and integrated AI workflows, these gateways are frequently positioned where they are reachable via network or internet segments. This placement increases the potential for unauthorized access compared to services strictly isolated within an internal, non-routable network.

What steps should I take if I run this technology?

First, conduct an inventory to identify every instance of the GitLab AI Gateway deployed within your environment. Since this component requires specific administrative or platform-level permissions, coordinate with your infrastructure and platform engineering teams to verify if your current versions fall within the affected range. Prioritize updates for any instances that are exposed to network segments, as these represent the highest risk for unauthorized access.

References