Sceawere
Vulnerability Detail
CVE-2026-90970UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
GitLab AI Gateway Sandbox Escape
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 8h ago
- Vendor
- GitLab
- Product
- GitLab AI Gateway
- Attack Type
- CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-02T15:17:12.550Z",
"pubdate": "2026-10-02T15:17:12.550Z",
"executiveSummary": "A critical security vulnerability has been identified within the GitLab AI Gateway, specifically concerning the prompt template sandbox environment. The vulnerability allows an authenticated user with access to the Duo Agent Platform to achieve arbitrary command execution on the host system. By submitting a specially crafted flow configuration, an attacker can bypass existing sandbox constraints. This vulnerability affects multiple versions of the AI Gateway, including 18.1.6 through 19.2.3, 19.3 through 19.3.1, and 19.4. The risk to the organization is significant, as it grants an authenticated malicious actor the capability to execute system-level commands, potentially leading to unauthorized data access, lateral movement within the infrastructure, and full compromise of the AI Gateway container or host. Exploitation requires the attacker to possess legitimate access to the Duo Agent Platform, making this a high-privilege escalation vector. Immediate remediation by updating to the patched versions—19.2.4, 19.3.2, or 19.4.1—is necessary to eliminate the attack surface and prevent potential system exploitation.",
"technicalDetails": "The vulnerability originates from insufficient isolation within the GitLab AI Gateway's prompt template processing logic. The component, which is responsible for managing and executing AI-driven agent workflows, failed to properly sanitize or validate user-provided flow configurations. This flaw allows a user to inject malicious payloads into the template engine that the AI Gateway uses to process Duo Agent interactions.\nThe root cause is a sandbox escape condition where the logical boundary between the restricted template execution environment and the underlying system environment is breached. When a crafted flow configuration is submitted, the AI Gateway's parsing mechanism incorrectly handles the input, permitting the execution of unauthorized commands outside of the intended, restricted sandbox runtime. Because the AI Gateway operates with the necessary permissions to interface with external LLMs and internal services, the resulting command execution inherits the privileges of the AI Gateway process itself.\nThe attack flow proceeds as follows: First, an attacker authenticates as a user with existing Duo Agent Platform access. Second, the attacker crafts a malicious flow configuration—a JSON or YAML-based object defining agent behavior—that incorporates payload vectors designed to manipulate the template engine's interpreter. Third, the attacker submits this payload via the standard configuration interface. Upon ingestion, the AI Gateway's vulnerable component processes the tainted configuration, failing to enforce sandbox restrictions. This triggers a breakout of the restricted runtime, enabling the payload to escape into the operating system level. Finally, the payload executes arbitrary system commands on the AI Gateway host, allowing the attacker to interact with the underlying file system, network, or environment variables.\nThis vulnerability is classified as an RCE (Remote Code Execution) facilitated by a sandbox escape. The affected versions are 18.1.6 through 19.2.3, 19.3.0, 19.3.1, and 19.4.0. The exploit does not require network-level access beyond what is already granted to an authenticated Duo Agent Platform user. The post-exploitation impact is severe, as it grants the attacker a foothold in the infrastructure, enabling the execution of arbitrary binaries, manipulation of configuration files, and potential exfiltration of sensitive AI tokens or data processed by the gateway."
}