GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1
🔗 CVE IDs covered (1)
📋 Description
We have released versions 19.2.4, 19.3.2, and 19.4.1 of the GitLab AI Gateway. These versions contain a critical security fix for GitLab Self-Hosted AI Gateway, and we strongly recommend that all GitLab Self-Managed customers with GitLab Self-Hosted AI Gateway installations update to one of these versions immediately. We have conducted targeted outreach to Self-Hosted AI Gateway customers prior to this release post with this guidance. A fix has already been deployed for GitLab-hosted AI Gateways. Customers using GitLab.com, GitLab Dedicated, and GitLab Self-Managed instances using a GitLab-hosted AI Gateway are protected and do not need to take action. Recommended Action We strongly recommend that all GitLab Self-Hosted AI Gateway installations running a version affected by the issue described below are upgraded to one of the patched versions listed above as soon as possible. Security fixes Table of security fixes Title Severity Improper Neutralization issue in custom flow prompt template impacts AI Gateway Critical CVE-2026-90970 - Improper Neutralization issue in custom flow prompt template impacts AI Gateway GitLab has remediated an issue in the GitLab AI Gateway that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, leading to arbitrary command execution on the AI Gateway. Impacted Versions: GitLab AI Gateway: all versions from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 CVSS 9.9 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H) Thanks invisiblemeerkat for responsibly disclosing this issue. Updating To update GitLab Self-Hosted AI Gateway, see the GitLab Self-Hosted AI Gateway install documentation. Receive Patch Notifications To receive release notifications via RSS, subscribe to our patch release RSS feed or our RSS feed for all releases.