Template-Injection
GitLab AI Gateway CVE-2026-90970: Prompt Template Sandbox Escape Gives Command Execution
GitLab patches CVE-2026-90970, a CVSS 9.9 Jinja2 prompt-template sandbox escape in self-hosted AI Gateway that lets an authenticated Duo Agent Platform user run arbitrary commands on the host.