GitLab's AI gateway let a prompt template run commands on the server, which is server-side template injection with a new place to live
2026-10-03Security
CVE-2026-90970 scores 9.9. A user with access to GitLab Duo's agent platform could write a flow configuration that broke out of the prompt-template sandbox and executed commands on the host. The bug class is twenty years old. What is new is that letting users write templates is now a product feature.