GitLab has patched a critical path traversal vulnerability, CVE-2026-85706, rated 10.0 on the CVSS scale. Unauthenticated attackers could exploit the Repository Commits API to read arbitrary files on affected GitLab CE/EE servers. The vulnerability affects versions from 18.7 through before 19.1.8, from 19.2 through before 19.2.6, and from 19.3 through before 19.3.2. Self-managed GitLab users should upgrade to 19.1.8, 19.2.6, or 19.3.2, then review logs and assess whether credentials may have been exposed.