What happened
GitLab remediated a critical template-injection / sandbox-escape in its AI Gateway component. Under certain conditions an authenticated Duo Agent Platform user could break out of the prompt-template sandbox via a specially crafted flow configuration, achieving arbitrary command execution on the AI Gateway. Published to NVD 2026-10-02.
Why it matters
The AI Gateway is the trust boundary sitting in front of GitLab's CI/CD and code-suggestion LLM traffic and typically holds the model provider keys. Command execution on it can expose or redirect LLM prompts/project data and pivot into the wider GitLab/CI environment, and it demonstrates that agent-aware prompt templating is itself a remote-code-execution surface.
Attack vector
A crafted Duo Agent flow configuration escapes the prompt-template sandbox (template injection, CWE-1336), allowing an authenticated user to execute arbitrary commands on the AI Gateway host that proxies LLM traffic.
Affected systems
GitLab AI Gateway 18.1.6 – 19.2.3, 19.3.0 – 19.3.1, 19.4.0 (fixed 19.2.4 / 19.3.2 / 19.4.1)
Mitigation
Upgrade the AI Gateway to 19.2.4, 19.3.2 or 19.4.1. Reference: https://gitlab.com/gitlab-org/gitlab/-/work_items/628842