GovKM
AI Gateway Workflow Authority and Template Sandbox Escape

The User Could Author a Workflow. The Template Engine Gave Them the Host.

GitLab’s critical AI Gateway flaw shows how valid workflow-authoring authority can cross a template boundary and become unauthorized host execution.
Governance illustration representing a GitLab Duo agent workflow configuration crossing from authorized prompt-template editing into unauthorized command execution on the AI Gateway host.
Expand image

Permission to author an agent workflow is not permission to control the machine that renders it.

GitLab’s October 2, 2026 critical AI Gateway patch disclosed CVE-2026-90970, a prompt-template neutralization flaw affecting self-hosted GitLab AI Gateway. Under certain conditions, an authenticated user with Duo Agent Platform access could submit a specially crafted custom-flow configuration, escape the prompt-template sandbox, and execute arbitrary commands on the gateway host. GitLab rated the vulnerability CVSS 9.9 and urged affected self-hosted customers to upgrade immediately. GitLab-hosted gateways had already been patched.

The continuity failure

The user’s identity and initial capability were legitimate. The user was allowed to configure an agent flow. The continuity break occurred when that authority crossed a semantic boundary:

Authority / configure workflow → Record / flow definition → Context / prompt-template renderer ✕→ Action / operating-system command.

The renderer transformed an authorized configuration artifact into an unauthorized execution capability. Valid authorship did not imply valid host authority.

Why this matters beyond one CVE

AI platforms increasingly convert natural-language instructions, workflow definitions, templates, skills, and tool schemas into executable behavior. Every transformation layer therefore becomes a governed actor. The question is not only who submitted the record, but which effects that record is allowed to produce after interpretation.

This complements GovKM’s earlier analysis of source-object authority in MCP actions: an operation can be valid while the specific object or downstream effect remains unauthorized.

The GovKM interpretation

A continuity-aware execution layer should bind each workflow artifact to an explicit effect envelope: permitted tools, filesystem reach, network scope, secrets exposure, subprocess authority, and resource limits. Crossing that envelope should require a new authority decision rather than inheriting permission from the fact that the workflow itself was validly created.

There is also a possible institutional-memory lesson. GitLab disclosed another critical template-expansion flaw in the AI Gateway earlier in 2026. GitLab has not stated that the October flaw shares the same root cause, so it would be incorrect to call this a failed patch. But repeated failures in the same transformation surface raise a useful governance question: did the earlier defect become a reusable design constraint for every template path, or remain evidence attached only to one CVE?

Continuity path: Source / user-defined agent flow → Evidence / validated configuration → Authority / workflow-edit permission → Context / AI Gateway renderer → Decision / render and execute → Action / host command → Record / gateway activity → Institutional Memory / security finding and design constraint → Future Reuse / later workflow implementations.

Source

GitLab, GitLab AI Gateway Critical Patch Release: 19.2.4, 19.3.2, and 19.4.1, October 2, 2026. https://docs.gitlab.com/releases/patches/other-patches/patch-release-gitlab-ai-gateway-19-4-1-released/

CVE-2026-90970, CVE Program.

RELATED KNOWLEDGE

Continue Exploring

Explore related research, framework domains, and continuity concepts.
CONTINUE WITH THE FRAMEWORK

Explore the continuity relationships that support trustworthy organizational intelligence.

Continue through the GovKM Framework to examine the doctrine, knowledge, and implementation guidance behind Organizational Continuity.