GitLab releases emergency patches for critical code execution flaw in AI Gateway

GitLab disclosed a critical remote code execution vulnerability in its AI Gateway service that could allow authenticated users with specific permissions to execute arbitrary commands on self-hosted instances. Tracked as CVE-2026-90970, the flaw stems from improper input handling in the prompt template sandbox that could be bypassed through specially crafted configurations. GitLab has released patched versions for self-managed customers and confirmed that cloud-hosted instances are already protected.
GitLab's AI Gateway enables developers to leverage artificial intelligence capabilities within the company's DevSecOps platform, which serves a massive user base including over half of Fortune 100 enterprises. The vulnerability allows authenticated users possessing specific platform permissions to circumvent security protections built into the prompt template sandbox through malicious configuration inputs, potentially compromising self-hosted deployments. GitLab proactively notified affected customers before public disclosure and released three patched versions to address the flaw across different release channels.
The vulnerability may significantly impact organizations running self-hosted AI Gateway instances, particularly those with strict data residency requirements or regulatory constraints preventing cloud-based solutions. Large enterprises and government agencies could face operational pressures balancing immediate patching needs against system stability concerns. Since GitLab serves critical infrastructure clients and government contractors, exploitation could potentially compromise development environments and sensitive project data, though the requirement for authenticated access limits the immediate risk surface compared to unauthenticated vulnerabilities.