In The Mobius Nexus, the first novel of the Mobius Nexus Cycle, glyphs come through the Lattice as executable code. They arrive looking like language and behave like programs, and receiving them turns out to be the same act as running them. The novel treats that as an alien problem. Now it has turned up in ordinary infrastructure.
On October 2 GitLab disclosed CVE-2026-90970, rated 9.9 out of 10, in the self-hosted AI Gateway that powers its Duo features. A user with access to its agent platform could submit a crafted flow configuration that escaped the sandbox where prompt templates are assembled and then ran commands on the gateway host (Rescana, October 2026). The model was never involved. The flaw sits in the template engine that builds the text the model will later read, and it carries CWE-1336, MITRE’s category for improper neutralization in a template engine. Put simply, a field that should have stayed text was read as an instruction. GitLab had fixed a similar 9.9 template flaw, CVE-2026-1868, in February.
The confusion is older than most working programmers. In 1988 the Morris worm entered some machines through the Unix finger service, which copied incoming text into a fixed-size buffer without checking its length. Input longer than the buffer overwrote the address that told the program where to return, and the processor jumped into bytes the sender had supplied as data. In 1996 Aleph One published the technique in Phrack as a step-by-step tutorial, and a decade of exploitation followed.
SQL Slammer showed what that meant at scale. In January 2003 it used a buffer overflow in Microsoft SQL Server, and the whole worm fit in a single network packet. Researchers found that it infected more than 90 percent of vulnerable hosts within ten minutes (CAIDA).
SQL injection, publicly described in 1998, moved the same confusion up a layer. A form field meant to hold a name could close the database query and append a command of its own. Template injection belongs to the same family. The mechanisms differ. An overflow corrupts memory, while an injection changes how a parser reads its input. What they share is untrusted content gaining influence over control.
Filtering never held for long, because every blocklist eventually lost to the input nobody had listed. The defenses that lasted moved the boundary to a place the attacker could not write. Data Execution Prevention, built into Windows since XP Service Pack 2, lets the system mark memory pages as non-executable so code cannot run from the stack or the heap (Microsoft). Microsoft is careful to say DEP is not a comprehensive defense, and memory corruption bugs are still found every month. Parameterized queries did similar work for databases by carrying the command and the user’s values through separate channels, though careless query construction can still bring injection back. The bug classes survived. What changed was where the decision about execution gets made.
AI systems have boundaries of their own. Developers separate system instructions from user input and restrict which tools a model may call. The hard limit is narrower. Labeling hostile text does not reliably stop a language model from treating it as an instruction, because the model’s usefulness depends on reading everything it is given. A memory page carries a bit that says whether it may execute. A sentence carries nothing of the kind.
That is the problem the glyphs pose. More careful reading cannot quarantine them, since reading is how they run. Whatever defends against them has to sit outside the reader.
The same holds for AI pipelines. Templates and generated code belong in isolated, unprivileged processes, so an escape lands somewhere with nothing worth taking. NIST SP 800-53 calls this SC-39, Process Isolation, and ITSP.10.033 carries the same control. Text from a user-authored flow should have no path to a command interpreter on the gateway, which is the information flow enforcement described in AC-4. Gateway hosts should hold no secrets an escape could reach, and consequential actions should wait for review. SI-16, Memory Protection, covers DEP and address randomization, and it stands in the catalog as a record of the last time this boundary was rebuilt.
Hostile text will keep arriving, and models will keep needing to read it. Text cannot carry its own permission bits. The system has to enforce them around it.
RECORD RETAINED
SOURCE INTEGRITY UNCONFIRMED


