GitLab’s Self-Hosted AI Gateway Needs an Immediate Update
GitLab urges immediate self-hosted AI Gateway upgrades for CVE-2026-90970. The 9.9 flaw could let an authenticated Duo Agent Platform user escape the prompt template sandbox through a crafted flow and execute arbitrary commands on the gateway.
Affected builds
- 18.1.6 to <19.2.4: install 19.2.4.
- 19.3 to <19.3.2: install 19.3.2.
- 19.4 to <19.4.1: install 19.4.1.
GitLab’s hosted gateway is fixed. GitLab.com, Dedicated and Self-Managed users routed there need no customer gateway patch. Self-Managed users running self-hosted gateways do. GitLab documents both paths.
BlackTree’s advice: identify each Duo feature’s gateway, update affected self-hosted builds, then verify the running version and feature route. A GitLab core update alone is insufficient.
GitLab gives no active-exploitation report; that does not prove none occurred.


