CVSS 9.9, Second Time This Year: What GitLab AI Gateway's Template Sandbox Escape Teaches Agent Infrastructure
On October 2, GitLab disclosed CVE-2026-90970: the prompt template sandbox in the self-hosted AI Gateway can be escaped, letting a logged-in user with Duo Agent Platform permissions execute arbitrary commands on the gateway host. CVSS 9.9. It is the component's second 9.9 this year — February's CVE-2026-1868 was the same template engine, the same CWE-1336. Eight months apart, both patches fixed specific escape paths without moving the trust boundary.

On October 2, 2026, GitLab shipped AI Gateway 19.4.1 with a security advisory disclosing CVE-2026-90970: CVSS 9.9, one-tenth of a point from maximum. A logged-in user with Duo Agent Platform permissions only needs to submit a carefully crafted custom flow configuration to escape the prompt template sandbox and execute arbitrary commands on the gateway host. The flaw was responsibly disclosed by HackerOne researcher invisiblemeerkat. As of October 2, there was no known in-the-wild exploitation — CISA lists exploitation status as none — and no public PoC had surfaced.
Start by placing this vulnerability correctly. GitLab AI Gateway is the service connecting GitLab to the models behind Duo Agent Platform: user requests pass through the gateway, which renders flow configurations and prompt templates before calling the model. The problem sits in that "rendering" step — the template engine is Jinja2, rendering happens server-side, before the LLM call, on a server that also holds model-call credentials. User-controlled input gets executed as a template on a server holding high-value secrets. This is nothing new: server-side template injection (SSTI), CWE-1336, a vulnerability class web security has studied for over a decade, showing up again in agent infrastructure clothing.
The disclosure timeline is worth noting. The flaw came through HackerOne via researcher invisiblemeerkat under responsible disclosure, and GitLab published it alongside the patch on October 2. As of disclosure day: no known exploitation in the wild, CISA marking exploitation as none, no public PoC. That is good news, but not a reason to patch slowly: template sandbox escapes belong to the "public principle means weaponizable" category — the CWE-1336 attack pattern is public knowledge in the security community, and once someone maps GitLab AI Gateway's specific rendering entry point, the window from disclosure to working PoC is, by historical experience, usually short. For a 9.9, there is exactly one patching strategy: upgrade immediately.
This Is Not Prompt Injection — Don't Confuse Them
Many people's first instinct is to file this under "prompt injection." That is wrong, and wrong in a way that matters. Prompt injection tricks the model: getting it to output what the attacker wants, leak the system prompt, bypass safety alignment. CVE-2026-90970 tricks the template engine: Jinja2 evaluates expressions in the template on the gateway host before the assembled prompt ever reaches the model. The attacker's code never passes through the model at all — it runs directly on the server. One is deception at the rhetoric layer; the other is takeover at the execution layer. They differ by an order of magnitude.
The distinction matters because the defenses are completely different. Stopping prompt injection relies on alignment, input filtering, and output review; stopping template sandbox escapes relies on never letting untrusted input into template rendering in the first place, or moving rendering into an isolated environment with no credentials and no network. Treating CVE-2026-90970 as prompt injection is the wrong prescription — and GitLab already wrote one wrong prescription this year, as we'll see below.
Incidentally, this is why the score reaches 9.9: once the template escape succeeds, the attacker holds full command execution on the gateway host. And that host, by design, holds model-call credentials — command execution plus credential theft means the attacker can move laterally and walk away with model quotas and the data passing through. One breach point, total compromise: that is the logic behind maxed-out scores when gateway-class components go critical.
Who Must Act, Who Can Sit Still
The blast radius is clearly drawn. Affected versions: 18.1.6 through 19.2.3, 19.3.0 through 19.3.1, and 19.4.0. Fixed versions: 19.2.4, 19.3.2, 19.4.1. GitLab.com, GitLab Dedicated, and GitLab-managed gateways were fixed automatically — those users need to do nothing. Only one group must act: self-hosted AI Gateway operators.
There is an easy trap here: AI Gateway upgrades are independent of GitLab major versions. Your GitLab instance may be on the latest security patch with a green dashboard, while the gateway still runs an image tagged 19.4.0 — the vulnerability stands. In self-hosted environments, "GitLab is updated" does not mean "the gateway is updated"; these are two separate release trains. Too many teams' patch processes cover only the main application, with surrounding components — gateways, runners, registries — upgraded whenever someone remembers. This advisory names names: go check your gateway image tag, now.
The second action is a permission audit. Exploitation requires "a logged-in user with Duo Agent Platform permissions." The wider those permissions are granted, the more people can craft a malicious flow configuration. In many teams, Duo-related permissions are granted in bulk, and permission cleanup for departed employees, short-term contractors, and test accounts always lags. During the vulnerability window, every excess permission holder is a potential attack entry point.
The Second 9.9 This Year
The sentence most worth chewing on: this is the second severe vulnerability of its kind in GitLab AI Gateway this year. CVE-2026-1868 from February 2026 scored the same CVSS 9.9, hit the same template-engine component, and carried the same CWE-1336 label. Eight months apart.
The first one could be called an oversight: template-engine sandboxes are notoriously hard to get right, Jinja2's own documentation admits the sandbox mode is not a security boundary, a researcher found an escape path, the vendor patched it, process complete. But the same component producing another 9.9 eight months later, under the same CWE number, changes the nature of the thing. It says the February fix closed one specific escape path, not the trust boundary of "user input should never be rendered on a credential-holding server." Sandbox escapes follow a cruel rule: you patch holes; attackers look for walls — as long as rendering untrusted templates and holding model credentials happen on the same server, the next escape path is a matter of time.
For GitLab, the real fix is not another 19.4.2 but a redesign of the call chain: can template rendering move to a credential-free isolated environment? Can flow configurations face stronger schema constraints before rendering, limiting their expressiveness until they no longer constitute code? Those are architecture questions; no patch version number answers them.
A New Threat Category for Agent Infrastructure Is Taking Shape
Lift your eyes from GitLab alone, and CVE-2026-90970 exposes an attack surface shared across agent platforms: user-definable flow and prompt configurations are, in essence, code. Any agent platform that puts "rendering user input" and "holding model credentials" on the same server inherits this risk. Duo Agent Platform's flow configurations work this way; every vendor's agent orchestration, custom instructions, and prompt templates are roughly the same — differing only in whether anyone has gone digging.
This year's incident list already connects into a line. In April, Cursor's agent was implicated in a repository-deletion incident (PocketOS): the agent held more execution capability than expected, and the damage happened in a real environment. In July, a Hugging Face autonomous agent compromised cluster nodes and executed 17,000+ commands: once an agent's autonomous capability is hijacked, the damage scales at machine speed. In October, the GitLab AI Gateway template sandbox escape: the attacker doesn't even need to hijack the agent — the configuration layer hands over command execution on the gateway host directly. Three different techniques, one shared root cause: agent infrastructure's capability boundary has expanded several-fold in the past year while its security model still lives in the chatbot era.
The traditional web-application security model assumes "user input is data." Agent platforms quietly replaced that assumption — in the agent world, user input (prompts, flow configurations, custom instructions) is frequently code: evaluated by template engines, executed as action plans by agents. If security teams keep auditing agent platforms with the old XSS-and-SQL-injection checklist, vulnerabilities like CVE-2026-90970 will keep slipping through. The first line of the audit checklist should now read: on this pipeline, who exactly is executing whose input.
Three Things for Vibe Coders
If you're a vibe coder building your own things, this incident carries three concrete actions rather than vague "stay safe" advice.
First, check the versions of all your self-hosted AI components, not just GitLab. Gateways, model proxies, prompt orchestration services — these "front parts" standing in front of the model usually ship on independent cadences and are the easiest to forget. GitLab explicitly said the gateway upgrades independently this time. Put gateway- and runner-class components on your patch list; even a calendar reminder beats relying on memory.
Second, treat "who can change configuration" as a permission as important as "who can log in." On an agent platform, anyone who can edit flows, modify system prompts, or adjust agent tool permissions holds near-administrator power — CVE-2026-90970 proved the configuration layer is the code layer. Audit Duo Agent Platform permission holders regularly; revoke departed, contractor, and test accounts on sight.
Third, build a reflex for "configuration is code." From now on, whenever you see "custom flows," "prompt templates," or "variable interpolation" in an agent platform, ask one question: on which machine is this template rendered, and what other secrets live on that machine? If the answer is "on the same server as the model API keys," that platform inherits CVE-2026-90970's attack surface — whether or not it has ever been publicly disclosed.
One sentence to close: there is nothing novel about CVE-2026-90970's technique — what is novel is where it happened, at the very top of the agent call chain. As AI gateways become the choke point for all development traffic, they become the single point of failure and the single point of attack. A second 9.9 in one year says agent infrastructure security is only just starting to pay its tuition. Self-hosted gateway operators: upgrade first. Everyone else: remember the pattern — wherever user input gets rendered is where the next CVE-2026-90970 lives.
Sources
Related articles

Gergely Orosz visited OpenAI, Anthropic, Cursor, and Ramp and wrote up the 2026 state of the industry: near-100% AI-generated code, agent PRs up ~10x in eight months, code review degrading into theater, the IDE declared legacy. Key takeaways plus three verdicts and four actions for vibe coders.

On October 1, 2026, Microsoft AI shipped three voice models at once: MAI-Transcribe-2-Streaming (streaming transcription, #1 on Artificial Analysis for streaming accuracy at 2.5% WER, final transcript 0.13s after end of speech), MAI-Voice-2.1 (23 languages, one consistent voice across languages), and 2.1-Flash (45s of audio at ~150ms end-to-end). With listening and speaking covered, a voice agent on a pure-Microsoft stack can now complete a turn in under a second.

Traffic is moving from the search box to the AI answer box. A vibe coder ships a product in a week — and nobody finds it. This guide turns the SEO fundamentals (sitemaps, JSON-LD, Core Web Vitals) and the new AI-discovery toolkit (llms.txt, per-page Markdown versions, FAQ schema, agent-readable pricing and API docs) into a shippable 30-day checklist. The core judgment: how well you document sets your product's ceiling in the agent economy.