# GitLab AI Gateway: flow templates and sandbox assumptions

The vendor describes a template sandbox escape. Authoring a workflow is therefore a security-sensitive capability even when the user does not hold host-administration rights.

## What deployment does this concern?

**Component and scope:** GitLab Duo Agent Platform flow-template processing.

**Affected versions / scope:** 18.1.6 to < 19.2.4; 19.3 to < 19.3.2; 19.4 to < 19.4.1

**Vendor remediation:** 19.2.4, 19.3.2 and 19.4.1

An authenticated user with access to the Duo Agent Platform can submit a crafted flow template to the affected template-processing path. This is an application-specific prerequisite.

## Vendor response and practical action

The vendor released branch-specific patches and states its hosted gateways were already fixed. Self-hosted operators retain their upgrade responsibility and should use the patch appropriate to their release branch.

Treat the vendor notice as the starting point for an applicability decision. Identify the installed artifact and configuration, document whether the prerequisite exists, and assign an owner to any required change. A public advisory does not establish that your installation was exposed or that a managed service shares the same condition.

## What clients can learn

Ask what an author can cause a workflow runtime to execute, read and contact. A template language or sandbox needs a defined permission boundary and a plan for patching that runtime.

A useful evaluation result connects a named control to evidence from the actual deployment. Keep the provider's statement, your effective configuration and a relevant demonstration together. If the result depends on a feature being disabled or a network being isolated, retain that fact with the version number so a later change triggers review.

## Questions to take to your provider

- Who can create and submit flow templates?
- Which AI Gateway branch and patch are installed?
- What host permissions and secrets are available to the runtime?
- Does a hosted-service patch cover your self-hosted components?

Use the [six-page evaluation worksheet](/assets/downloads/ai-gateway-evaluation-worksheet.pdf) to record evidence, ownership and actions. Continue with [AI gateway security: protect the boundaries that matter](/resources/ai-gateway-security) for the wider evaluation context.

### Technical detail: evidence and identifier limits

This case describes GitLab's application-specific gateway. It is not a generic finding against interchangeable AI model gateways.

- Vendor identifier: CVE-2026-90970. Keep branch-specific intervals separate.

Evidence label: **security advisory**. Source-review date: **2026-10-07**. A publication date is not stated in the linked release notice. Review and article dates do not change merely because this article is rebuilt.

## Primary sources

- [GitLab AI Gateway patch release notice](https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/)


---
Published: 2026-10-07. Modified: 2026-10-07. Sources reviewed: 2026-10-07.

Author: OneQuill Research. Affiliation: OneQuill develops OneVir. Documentary review; selected case totals are not vendor security rankings.
