The Prompt Template Was an RCE Boundary
A prompt template is supposed to shape what an AI system says.
In GitLab’s self hosted AI Gateway, a flaw in the template path could instead let an authenticated user escape the prompt template sandbox and execute arbitrary commands on the gateway.
That is the important boundary failure in CVE-2026-90970. The model was not the exploit primitive. The control plane that prepared model requests was.
What changed
GitLab published a critical security release for its self hosted AI Gateway with versions 19.2.4, 19.3.2, and 19.4.1. GitLab’s patch notice recommends that affected installations upgrade immediately.
The CVE record describes an improper neutralization issue in the AI Gateway template engine. Under certain conditions, an authenticated user with Duo Agent Platform access could use a specially crafted flow configuration to escape the prompt template sandbox. The stated result was arbitrary command execution on the AI Gateway.
GitLab assigned the issue a CVSS 3.1 score of 9.9, with network attack vector, low attack complexity, low privileges required, and high impact to confidentiality, integrity, and availability. The record lists CWE-1336, improper neutralization of special elements used in a template engine.
The affected ranges are:
| Component | Affected versions | Fixed version |
|---|---|---|
| GitLab AI Gateway | 18.1.6 through before 19.2.4 | 19.2.4 |
| GitLab AI Gateway | 19.3 through before 19.3.2 | 19.3.2 |
| GitLab AI Gateway | 19.4 through before 19.4.1 | 19.4.1 |
GitLab says the fix was already deployed for GitLab hosted AI Gateways. GitLab.com, GitLab Dedicated, and self managed installations using a GitLab hosted gateway do not need the self hosted upgrade described in the notice.
The model is not the boundary
The word prompt makes this vulnerability easy to misclassify.
A prompt template is text, but a template engine is an interpreter. It has syntax, escaping rules, variables, helper functions, and a runtime context. Once a user controlled flow configuration can cross from that interpreter into the host process, the system is no longer just formatting a request for a model.
It is evaluating configuration with authority.
That distinction appears throughout agent infrastructure. A tool schema looks like data until a runner turns it into a process invocation. A workflow file looks declarative until the scheduler gives it credentials. A model configuration looks inert until a loader deserializes it or a runtime expands it.
The security property is determined by the interpreter and the authority behind it, not by the label attached to the input.
flow configuration
|
v
prompt template engine
|
v
sandbox boundary
|
v
AI Gateway process and host
The exact exploit details are not public in GitLab’s patch notice, and the CVE is precise about the required access rather than publishing an operational recipe. What is confirmed is enough for the architectural conclusion: a crafted flow configuration could cross the template sandbox and reach arbitrary command execution.
Why the gateway matters more than the model
An AI Gateway sits between users, model providers, policy, credentials, and downstream services. It may render prompts, attach context, select models, broker tools, and record traces.
That makes it a high value control plane. Compromising the model output is one problem. Compromising the service that assembles requests and holds the integration authority is another.
The CVE’s impact follows from that position. Command execution on the gateway can expose secrets available to the gateway, alter the code or configuration used for later requests, tamper with traces, or pivot toward connected services. Those consequences are an inference from the gateway’s role, not a claim that GitLab’s notice documents each outcome for this issue.
The confirmed facts are narrower: affected self hosted versions existed, the vulnerable path required an authenticated user with Duo Agent Platform access, the path involved custom flow prompt templates, and GitLab rated the resulting impact as critical.
That separation matters. Security writing should not inflate a patch notice into a breach report. A high severity score describes the potential impact of the vulnerability under its stated conditions. It does not prove that a particular deployment was compromised.
The common intuition gets the trust boundary wrong
Agent security discussions often focus on prompt injection. That is useful when an attacker is trying to influence a model’s behavior through content.
CVE-2026-90970 belongs to a different class. The attacker does not need the model to agree with a malicious instruction. The attacker targets the machinery that turns configuration into a model request.
The model could refuse every dangerous request and the gateway could still be compromised before inference. A refusal policy cannot repair a template interpreter that crosses into host authority.
This is the uncomfortable operational lesson: the model is only one participant in the control loop. The template engine, flow loader, credential broker, tool runner, plugin manager, and logging path all deserve the same threat model.
What operators should do
Patch the self hosted gateway. Upgrade affected installations to 19.2.4, 19.3.2, or 19.4.1 according to the version line. Do not assume that a GitLab instance is protected merely because the model provider is hosted elsewhere. Confirm which AI Gateway is actually serving the traffic.
Inventory flow authors and permissions. The CVE requires an authenticated user with Duo Agent Platform access. Review who can create or modify custom flows, who can publish them, and whether those actions are logged. Least privilege is more useful here than a blocklist of suspicious strings.
Treat templates as code. Apply parser isolation, explicit escaping, capability restrictions, and resource limits to every template engine. A configuration format that can call helpers, access files, or reach the process environment is a programming language whether the product documentation calls it one or not.
Separate rendering from authority. The component that renders a prompt should not automatically have the credentials and process permissions of the gateway. Put command execution, secret access, and tool brokering behind narrow interfaces with independent authorization and audit records.
Test the control plane without the model. Security tests should send crafted configuration to the flow and template layers directly. The model is not required for this class of failure, so model evaluations alone will miss it.
The prompt was never just text
GitLab’s patch is a product specific fix. The broader lesson applies to every agent stack that lets users define flows, tools, prompts, or routing policies.
The moment a text format is interpreted, it becomes part of the executable attack surface. The moment its output controls a privileged service, the interpreter becomes a trust boundary.
The right question is not whether the model saw a malicious prompt. It is whether an untrusted configuration could make the system do something the operator did not authorize.
In an agent system, the prompt template can be an RCE boundary long before the model is asked to answer anything.
Sources
- GitLab AI Gateway Critical Patch Release (affected versions, fixed versions, hosted versus self hosted status, vulnerability description, and recommended action)
- CVE-2026-90970 record (description, CWE, CVSS score, affected ranges, and required access)
- NVD entry for CVE-2026-90970 (independent record of the affected ranges, CNA score, and publication date)
- The Cyber News radar post (discovery context; the technical claims above come from GitLab and CVE records)
Method note: this article was selected from exactly two free, session authenticated twsearch radar queries: AI agent security CVE OR vulnerability and open weights model release. The vulnerability claims were checked against GitLab’s patch notice, the CVE record, and NVD. The impact discussion distinguishes confirmed facts from inference about the role of an AI Gateway.