The breach isn’t the problem. The spread is. →Free Assessment

Executive Summary

GitLab disclosed a critical vulnerability (CVE-2026-90970) with a CVSS score of 9.9 affecting its AI Gateway service, allowing authenticated users with Duo Agent Platform access to execute arbitrary commands on self-hosted gateway instances. The flaw enables prompt template sandbox escapes through specially crafted flow configurations, potentially compromising gateway infrastructure that holds sensitive JWT signing keys and connects to AI model providers. GitLab has patched the vulnerability in gateway versions 19.2.4, 19.3.2, and 19.4.1, and strongly recommends immediate updates for self-hosted deployments.

This incident highlights the growing attack surface of AI-integrated development platforms as organizations increasingly adopt AI-powered workflows and autonomous systems, making secure AI gateway configurations critical for preventing unauthorized access to sensitive AI infrastructure and model interactions.

Why This Matters Now

AI gateway vulnerabilities are becoming critical attack vectors as organizations rapidly deploy AI-powered development tools without proper security controls, creating new pathways for privilege escalation and command execution in cloud-native environments.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

All self-hosted AI Gateway versions from 18.1.6 through 19.4.0 are affected. Fixed versions are 19.2.4, 19.3.2, and 19.4.1.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would likely constrain this GitLab AI Gateway compromise by limiting lateral movement through segmentation and controlling egress paths for sensitive data exfiltration.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Comprehensive network visibility and policy enforcement would likely detect and constrain the exploitation of prompt template injection vulnerabilities through anomalous traffic patterns

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload isolation and micro-segmentation would likely limit the attacker's ability to access JWT signing keys and service credentials beyond the compromised container scope

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation and east-west traffic controls would likely constrain lateral movement between GitLab instances and AI model provider environments through policy-based access restrictions

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Cross-cloud visibility and traffic analysis would likely detect anomalous communication patterns between compromised gateways and external AI model provider connections

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely limit unauthorized data exfiltration by restricting outbound traffic patterns and data transfer volumes from compromised AI gateway services

Impact (Mitigations)

While AI response manipulation may still occur within the compromised gateway, the scope of workflow disruption would likely be constrained to segmented workloads

Impact at a Glance

Affected Business Functions

  • DevOps Pipeline Management
  • AI-Powered Development Tools
  • Source Code Management
  • Continuous Integration/Continuous Deployment
Operational Disruption

Estimated downtime: 1 days

Financial Impact

Estimated loss: N/A

Data Exposure

Potential exposure of GitLab instance data, AI model request/response data, and JSON Web Token signing keys stored on self-hosted AI gateways. Risk limited to organizations using self-hosted gateway deployments.

Recommended Actions

  • • Deploy Cloud Native Security Fabric (CNSF) with inline inspection to detect and block prompt injection attempts and malicious AI agent behaviors in real-time
  • • Implement Zero Trust Segmentation around AI Gateway containers with least-privilege access controls and service-to-service authentication
  • • Enable Egress Security & Policy Enforcement to monitor and restrict AI Gateway outbound connections to authorized AI model providers only
  • • Deploy Multicloud Visibility & Control to baseline normal AI Gateway traffic patterns and detect anomalous automation or repeated malformed requests
  • • Establish Threat Detection & Anomaly Response capabilities specifically tuned for AI workload behaviors and unauthorized command execution patterns

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image