GitLab has released a patch for a critical vulnerability in its AI Gateway, tracked as CVE-2026-90970. According to GitLab's official security advisory, an authenticated user with access to the Duo Agent Platform could escape the prompt sandbox and execute arbitrary commands on self-hosted Gateway hosts. Security Affairs also reported the flaw on 3 October. Readers should consult GitLab's advisory directly for the full list of affected and patched version numbers, and for the officially published CVSS score — third-party coverage cites a score as high as 9.9.
The vulnerability is a "sandbox escape → command execution" attack chain. Authentication is a prerequisite, which raises the exploitation threshold rather than lowering it — but that also explains the advisory's very high score: the bar is high, but the consequence is direct command execution on the host, not merely a content-layer risk.
Why It Matters
AI Gateway components are often treated as a simple "model proxy" layer, yet they typically run with elevated privileges, hold access to model keys, API credentials and internal data. A sandbox escape here should therefore be treated as an application-security defect, not a model-security problem — the remediation targets isolation and permission models, not prompt content. Teams whose generative-AI governance focuses only on content filtering and data-exfiltration policy are the most exposed to this class of flaw.
Three Immediate Actions
- Check versions — inventory the versions of AI Gateway and related Duo components in your self-hosted environment against the affected-versions list in GitLab's advisory.
- Apply the patch — upgrade to the patched version specified in the advisory. If an immediate upgrade is not feasible, review whether access-control settings can block the attack path in the meantime.
- Audit Duo seats and entitlements — review who holds Duo Agent Platform access, and check existing audit logs for anomalous activity.
Component Impact Scope
Exact affected and patched versions must be taken from GitLab's official security advisory. Note that the AI Gateway component may ship on a different release cadence from the GitLab main application — if the advisory lists them separately, follow the component version. The table below outlines the components to watch, not a version list.
| Component | Status | Recommended Action |
|---|---|---|
| AI Gateway (self-hosted) | Affected | Compare with the advisory's affected-versions list; upgrade to a patched version |
| Duo Agent Platform access | Indirectly affected | Audit seats/entitlements; check audit logs |
| GitLab Cloud (managed) | Status unconfirmed | Verify against the advisory whether any customer-side action is required |
Whether GitLab-managed environments are affected, or have been patched automatically by GitLab, should be established from the current wording of the advisory — not inferred from secondary reporting.
Implications for Self-Hosted Deployments
For teams that run self-hosted GitLab as their DevOps backbone, the implication is direct: self-hosting places the remediation burden on the operator — a vulnerability notice does not automatically become a fix. Where the AI Gateway processes personal data, the operator as data user bears responsibility for security measures across outsourced processing, including AI services. A broken sandbox means a failure of control over the processing environment, and should be recorded as such in risk assessments and breach-response planning. (This is a general risk-management observation, not legal advice.)
Sources: GitLab's official security advisory (https://gitlab.com/gitlab-org/security/advisories — see the advisory entry for CVE-2026-90970); Security Affairs report, 3 October 2026 (https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html). For affected versions and patch details, consult GitLab's official advisory.
GitLab 已針對自家 AI Gateway 一項嚴重漏洞發布修補,編號 CVE-2026-90970。根據 GitLab 官方安全公告,已透過 Duo Agent Platform 取得存取權限的認證使用者,可逃離提示(prompt)沙盒,進而在自架(self-hosted)環境的 Gateway 主機上執行任意指令。Security Affairs 亦於 10 月 3 日報導此事。確切受影響與已修補的版本清單、以及官方公佈的 CVSS 評分(第三方報導指高達 9.9),可查閱 GitLab 官方安全公告。
此漏洞是一條「AI 沙盒逃逸 → 命令執行」的攻擊鏈。攻擊前提是需要已認證身分,這點確實提高了實際被利用的門檻——需認證才能利用,也解釋了為何公告仍給予極高評分:門檻高,但後果是直接在主機上執行指令,而非只是內容層面的風險。
為何值得重視
AI Gateway 通常被視為單純的「模型代理」層,卻往往以高權限身分執行、接觸模型金鑰、API 憑證與內部資料。因此,沙盒逃逸應被視為應用程式安全缺陷,而非模型安全問題——修補的對象是隔離機制與權限模型,而不是提示內容本身。若團隊的生成式 AI 治理只放在內容過濾與資料外洩政策,這類漏洞正是容易被忽略的一環。
三個立即動作
- 查版本 — 盤點自架環境中 AI Gateway 與 Duo 相關元件的版本,對照 GitLab 官方公告列出的受影響版本。
- 套用修補 — 升級至公告指定的已修補版本;若短期無法升級,檢視是否有可先行阻擋的存取控制設定。
- 稽核 Duo 席位與授權 — 盤點誰有 Duo Agent Platform 存取權限,並審視既有稽核紀錄是否出現異常活動。
元件影響範圍
確切的受影響版本與已修補版本,請一律以 GitLab 官方安全公告為準。另需留意,AI Gateway 元件的發版節奏可能與 GitLab 主應用程式不同,公告若有分別列示,應以該元件的版本為準。下表列出的是應關注的元件範圍,而非版本清單。
| 元件 | 狀態 | 建議行動 |
|---|---|---|
| AI Gateway(自架) | 受影響 | 對照官方公告受影響版本清單,升級至已修補版本 |
| Duo Agent Platform 相關存取 | 間接受影響 | 稽核席位與授權、檢查稽核紀錄 |
| GitLab Cloud 托管服務 | 狀態未確認 | 請直接查證 GitLab 公告中關於雲端服務的說明,確認是否需要客戶端行動 |
關於雲端託管環境是否受影響、以及是否已由 GitLab 代為修補,應以官方公告的最新敘述為依據,不宜僅憑第三方轉述下結論。
對自架部署團隊的啟示
對以自架 GitLab 作為 DevOps 核心的團隊而言,此漏洞的含意尤其直接:自架環境意味著修補責任落在使用者自己身上——漏洞通知不會自動轉化為修復動作。若 AI Gateway 處理的資料包含個人資料,企業作為資料使用者,對委外(包括 AI 服務)處理環節的安全措施負有責任;沙盒失守即代表資料處理環境的控制失效,這在風險評估與資料外洩應變規劃中應被如實記錄。(以上為風險管理層面的一般觀察,不構成法律意見。)
資料來源: GitLab 官方安全公告(https://gitlab.com/gitlab-org/security/advisories — 可查閱與 CVE-2026-90970 對應的公告條目);Security Affairs 於 2026 年 10 月 3 日的報導(https://securityaffairs.com/200283/hacking/cve-2026-90970-critical-gitlab-ai-gateway-flaw-fixed.html)。具體版本與修補細節請查閱 GitLab 官方安全公告。
