GitLab has issued crucial security updates to address a critical vulnerability in its AI Gateway that could enable authenticated users to execute commands remotely. Identified as CVE-2026-90970, this flaw has a CVSS score of 9.9, highlighting its severity. It specifically impacts self-hosted deployments that support GitLab Duo AI features. To mitigate this risk, GitLab has released AI Gateway versions 19.2.4, 19.3.2, and 19.4.1, urging users of affected self-hosted gateways to upgrade immediately. This vulnerability stems from improper handling of custom flow prompt templates. An authenticated user with access to the Duo Agent Platform could exploit this by submitting a specially crafted configuration, potentially breaching the sandbox environment meant to contain template processing. This breach could allow arbitrary command execution on the AI Gateway, posing significant risks to confidentiality, integrity, and availability. Although the vulnerability requires an authenticated account, its potential impact is substantial. GitLab has acknowledged security researcher invisiblemeerkat for responsibly reporting the issue. There is no current evidence of active exploitation, nor does the advisory include exploit details. However, the vulnerability affects AI Gateway versions starting at 18.1.6 up to versions before 19.2.4, the 19.3 branch prior to 19.3.2, and the 19.4 branch before 19.4.1. Administrators should verify their gateway deployments rather than relying solely on the main GitLab version. While GitLab.com and GitLab hosted services are already secured, self-hosted AI Gateway administrators must apply the update themselves. Detailed instructions are provided in GitLab’s installation and upgrade documentation, which includes guidelines for both Docker and Kubernetes deployments. Immediate upgrades are essential to ensure system security.