Critical GitLab AI Gateway Vulnerability Highlights the Security Risks of AI Powered Development

Artificial intelligence is becoming deeply integrated into modern software development. AI assistants and agent platforms can analyze code, automate development tasks, interact with repositories, and support engineering teams across the software lifecycle.

But as AI becomes connected to development infrastructure, it also creates new security boundaries that organizations need to protect.

A newly disclosed critical vulnerability in the GitLab AI Gateway highlights this risk. Tracked as CVE-2026-90970, the vulnerability has been rated CVSS 9.9 Critical and could, under certain conditions, allow an authenticated user with Duo Agent Platform access to escape a prompt template sandbox and execute arbitrary commands on the AI Gateway.

The issue is particularly important for organizations operating self hosted AI Gateway environments because the gateway sits between GitLab infrastructure and AI powered development capabilities.

What Happened?

GitLab identified and fixed an improper neutralization vulnerability involving custom flow prompt templates within its AI Gateway.

The vulnerability affects specific versions of GitLab AI Gateway:

• Versions from 18.1.6 before 19.2.4
• Versions from 19.3 before 19.3.2
• Versions from 19.4 before 19.4.1

GitLab has released patched versions 19.2.4, 19.3.2, and 19.4.1. The company also states that fixes have already been deployed to GitLab hosted AI Gateways.

The vulnerability is associated with CWE-1336, which covers improper neutralization of special elements used in template engines.

How the Vulnerability Could Lead to Code Execution

The issue involves specially crafted flow configurations within the Duo Agent Platform.

Under certain conditions, an authenticated user with appropriate Duo Agent Platform access could potentially escape the prompt template sandbox.

This could allow arbitrary command execution on the AI Gateway itself.

This is an important distinction.

The vulnerability does not mean that every GitLab installation is automatically vulnerable to unauthenticated remote compromise.

The documented attack scenario requires authenticated access and specific interaction with the affected AI functionality.

However, code execution on an AI Gateway can still create serious security implications because AI infrastructure may interact with source code, development workflows, repositories, authentication mechanisms, and external AI model providers.

Why AI Gateways Are Becoming a Security Boundary

AI gateways are increasingly becoming an important component of enterprise AI architecture.

They can connect:

• Development platforms
• AI models
• AI agents
• Developer workflows
• APIs
• Authentication systems
• Source code repositories
• Enterprise applications

This makes the gateway more than a simple network service.

It can become a central control point for AI related requests, responses, authentication, and workflow execution.

GitLab’s documentation notes that self hosted AI Gateway deployments use signed JSON Web Tokens for authentication and require sensitive signing keys to be configured within the environment.

A compromise of such infrastructure could therefore have consequences beyond the AI service itself, depending on how the environment is configured and what permissions and connections are available.

The Broader Risk of AI Development Platforms

This vulnerability is part of a broader security challenge emerging around AI assisted development.

AI systems increasingly have the ability to:

• Analyze source code
• Access repositories
• Execute development tasks
• Interact with CI/CD pipelines
• Generate and modify files
• Call external tools
• Access APIs
• Process developer supplied instructions

Every additional capability creates another potential security boundary.

If an AI agent or gateway is compromised, attackers may attempt to use those legitimate capabilities to move deeper into development environments.

This is why AI security needs to extend beyond the model itself.

Prompt Templates Can Become an Attack Surface

Traditional software security often focuses on input validation, authentication, authorization, and secure coding.

AI enabled applications add another dimension.

Prompt templates, agent workflows, tool definitions, external content, and user supplied instructions can all influence AI system behavior.

When those inputs interact with execution environments, inadequate isolation or validation can potentially create serious security consequences.

The GitLab vulnerability demonstrates why AI workflow configuration should be treated as part of the application’s security architecture rather than simply as an AI functionality.

What Organizations Should Do

Organizations operating self hosted GitLab AI Gateway deployments should review their environments and apply the appropriate security updates.

1. Identify Affected AI Gateway Deployments

Security teams should determine whether self hosted AI Gateway installations are running affected versions.

2. Apply GitLab Security Updates

GitLab recommends upgrading affected self hosted installations to patched versions. The current critical release includes versions 19.2.4, 19.3.2, and 19.4.1.

3. Review AI Agent Permissions

Organizations should determine what users, agents, workflows, and services can interact with AI Gateway functionality.

Least privilege should apply to AI systems just as it does to traditional applications and service accounts.

4. Protect AI Gateway Credentials

Self hosted AI Gateway environments can contain sensitive signing keys and other credentials. These should be protected through appropriate secrets management, access restrictions, monitoring, and rotation procedures.

5. Monitor for Suspicious Activity

Security teams should review:

• Authentication activity
• AI workflow configurations
• Gateway commands
• Unexpected process execution
• Configuration changes
• Network connections
• API activity
• Privilege changes
• Unusual repository access

6. Test AI Development Workflows

Security assessments should include AI agents, prompt templates, custom workflows, API integrations, CI/CD pipelines, and other components surrounding AI enabled development.

7. Review Segmentation

AI infrastructure should be appropriately segmented from production systems and other sensitive enterprise environments.

Compromise of an AI development component should not automatically provide unrestricted access to critical infrastructure.

Why This Matters for Software Supply Chain Security

Modern development environments are highly interconnected.

A developer may interact with:

Git repositories → AI agents → AI Gateway → CI/CD pipeline → cloud infrastructure → production systems.

Each connection introduces security considerations.

Recent supply chain incidents have also highlighted how attackers are increasingly targeting build and development pipelines because of the access they provide to downstream environments.

AI is now becoming another component within this ecosystem.

Organizations therefore need to secure not only their applications but also the AI systems that help create and operate those applications.

Industries That Should Pay Attention
Financial Services and Banking

Banks and financial institutions increasingly use AI for software development, customer applications, analytics, fraud detection, and internal automation. Security teams should carefully protect AI development infrastructure that may interact with sensitive financial systems and source code.

Healthcare and Life Sciences

Healthcare organizations developing digital applications need to protect source code, patient data, APIs, and AI enabled development environments while maintaining regulatory requirements.

Retail and E-commerce

Retail organizations depend heavily on cloud applications, APIs, customer platforms, and automated development pipelines. Compromise of development infrastructure could create downstream application and data security risks.

Manufacturing and Industrial Organizations

Manufacturers increasingly use software and AI across supply chain, engineering, operational technology, and enterprise environments. Segmentation and access control are particularly important when development systems connect to operational infrastructure.

Government

Government agencies managing sensitive applications and digital services should carefully control AI development infrastructure, developer identities, repositories, and connected systems.

Technology and SaaS Companies

Technology companies and SaaS providers are likely to have extensive AI enabled development environments. Source code, customer data, cloud credentials, CI/CD systems, and production infrastructure can all become high value assets requiring protection.

The Bigger Lesson for Enterprise AI

The GitLab AI Gateway vulnerability demonstrates that AI security cannot be separated from traditional application and infrastructure security.

Organizations adopting AI agents and AI powered development platforms should consider them part of the broader enterprise attack surface.

Security programs should include:

• AI application security
• Secure AI architecture
• Identity and access management
• Least privilege
• Prompt injection testing
• Secure agent design
• API security
• Secrets management
• CI/CD security
• Cloud security
• Vulnerability management
• Continuous monitoring
• Incident response

AI systems should be designed with security controls from the beginning rather than treated as an additional layer after deployment.

Conclusion

The critical GitLab AI Gateway vulnerability is another reminder that AI powered development infrastructure is becoming an important cybersecurity boundary.

CVE-2026-90970 demonstrates how weaknesses in AI workflow and template processing can potentially move beyond an AI interaction and result in command execution on the underlying gateway. GitLab has released security updates for affected self hosted versions, while GitLab hosted AI Gateways have already received the fix.

As organizations give AI systems greater access to development environments, repositories, APIs, and enterprise applications, security teams need to evaluate these systems with the same level of rigor applied to other privileged infrastructure.

AI can accelerate software development, but its supporting infrastructure must be secured with strong authentication, least privilege, isolation, monitoring, vulnerability management, and continuous security testing.

About COE Security

COE Security partners with organizations in financial services, healthcare, retail, manufacturing, and government to secure AI-powered systems and ensure compliance.

Our offerings include:

• AI-enhanced threat detection and real-time monitoring
• Data governance aligned with GDPR, HIPAA, and PCI DSS
• Secure model validation to guard against adversarial attacks
• Customized training to embed AI security best practices
• Penetration Testing (Mobile, Web, AI, Product, IoT, Network & Cloud)
• Secure Software Development Consulting (SSDLC)
• Customized CyberSecurity Services

COE Security also helps organizations secure AI enabled development environments through AI security assessments, application security testing, secure AI architecture reviews, vulnerability management, API security testing, cloud security assessments, CI/CD security reviews, identity and access management assessments, penetration testing, and secure software development practices.

For financial services and banking, we help protect AI development platforms, APIs, cloud environments, financial applications, source code, and sensitive customer information.

For healthcare and life sciences, we help strengthen AI security, application security, data protection, cloud environments, and compliance aligned security controls.

For retail and e-commerce, we help secure customer applications, APIs, cloud infrastructure, development pipelines, and AI enabled business systems.

For manufacturing and industrial organizations, we support secure development, network and cloud security, application testing, infrastructure assessments, and protection of connected digital environments.

For government organizations, we help strengthen AI governance, identity controls, application security, vulnerability management, cloud security, and protection of sensitive digital services.

For technology and SaaS companies, we help assess AI gateways, AI agents, development platforms, APIs, CI/CD pipelines, cloud environments, source code security, and software supply chain risks.

Our goal is to help organizations adopt AI securely while strengthening application security, protecting sensitive information, improving cyber resilience, and maintaining compliance with evolving cybersecurity and privacy requirements.

Follow COE Security on LinkedIn for ongoing insights into safe, compliant AI adoption and to stay updated and cyber safe.

Click to read our LinkedIn feature article