GitLab Patches Critical CVSS 10.0 Path Traversal Flaw Exploited Within a Day
GitLab has disclosed a maximum-severity path traversal vulnerability, CVE-2026-85706, affecting self-managed Community and Enterprise Edition instances. The flaw resides in the commit API and allows unauthenticated attackers with network access to read arbitrary files on the server by manipulating the file.path parameter. Active scanning targeting vulnerable instances was observed just one day after public disclosure. Successful exploitation could expose credentials stored in configuration files or logs, potentially enabling unauthorized access to repositories, CI/CD pipelines, and integrated cloud services. GitLab has released patched versions 19.1.8, 19.2.6, and 19.3.2, and urges administrators to update immediately and rotate any secrets that may have been exposed.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in