Skip to content
cve — cve-2026-90970

grep -rl "CVE-2026-90970" ./articles

CVE-2026-90970

CVE-2026-90970 scores 9.9. A user with access to GitLab Duo's agent platform could write a flow configuration that broke out of the prompt-template sandbox and executed commands on the host. The bug class is twenty years old. What is new is that letting users write templates is now a product feature.

1 article — 2026-10-03

Authoritative record

Root Notes reports on this identifier; it does not maintain it. For the vendor advisory, the affected versions and the scoring, NVD and MITRE hold the primary records.

Our coverage

../cve — every identifier we have covered