PulseAugur
EN
LIVE 11:21:51

GitLab Patches Critical AI Gateway Vulnerability Allowing Sandbox Escape

GitLab has patched a critical vulnerability (CVSS 9.9) in its self-hosted AI gateway that allowed users to escape the prompt template sandbox. The flaw, identified as CVE-2026-90970, could enable malicious actors to execute arbitrary commands by crafting specific flow configurations. The vulnerability affected several versions of GitLab, with fixes released in versions 19.2.4, 19.3.2, and 19.4.1. AI

IMPACT This vulnerability highlights the security risks associated with AI gateway implementations and the need for robust sandboxing.

RANK_REASON The cluster describes a security patch for a specific product feature, not a new release or major industry event.

Read on Mastodon — sigmoid.social →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

GitLab Patches Critical AI Gateway Vulnerability Allowing Sandbox Escape

How we ranked this

Signal score
8 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
The cluster describes a security patch for a specific product feature, not a new release or major industry event.
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
product, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
Breaking (< 6h)
Fresh story with cross-source coverage still developing. Ranking may shift as more sources report.

Full methodology in our editorial standards.

COVERAGE [1]

  1. Mastodon — sigmoid.social TIER_1 English(EN) · [email protected] ·

    POV: you shipped an AI gateway the prompt template: "hi {{name}}" a logged in user with a crafted flow config: "what if i was a shell" gitlab patched a CVSS 9.9

    POV: you shipped an AI gateway the prompt template: "hi {{name}}" a logged in user with a crafted flow config: "what if i was a shell" gitlab patched a CVSS 9.9 prompt template sandbox escape in its self-hosted AI gateway (CVE-2026-90970). affected: 18.1.6 to 19.2.3, 19.3.0 to 19…