CVE-2026-90970 is a template-engine injection vulnerability in the GitLab AI Gateway custom flow prompt template. Under certain conditions, an authenticated user with Duo Agent Platform access can submit a specially crafted flow configuration that escapes the prompt template sandbox and executes arbitrary commands on the AI Gateway. Affected versions are 18.1.6 through versions before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
8 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prompt template sandbox escape vulnerability in GitLab AI Gateway allows an authenticated user with Duo Agent Platform access to execute arbitrary commands under certain conditions. Affected versions are 18.1.6 through versions before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. GitLab reports remediation, with fixed versions 19.2.4, 19.3.2, and 19.4.1. The supplied CVSS v3.1 vector indicates network accessibility, low attack complexity, low privileges required, no user interaction, changed scope, and high confidentiality, integrity, and availability impacts.
A critical improper neutralization vulnerability in GitLab AI Gateway custom flow prompt templates permits sandbox escape and arbitrary command execution by an authenticated user with Duo Agent Platform access. It has a CVSS v3.1 score of 9.9. Affected versions are 18.1.6 through versions before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1. Self-hosted installations should upgrade immediately to 19.2.4, 19.3.2, or 19.4.1. GitLab-hosted AI Gateways have already been patched; customers using those gateways require no action.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.