GitLab has patched a critical path traversal vulnerability, CVE-2026-85706, rated 10.0 on the CVSS scale. Unauthenticated attackers could exploit the Repository Commits API to read arbitrary files on affected GitLab CE/EE servers.
The vulnerability affects versions from 18.7 through before 19.1.8, from 19.2 through before 19.2.6, and from 19.3 through before 19.3.2. Self-managed GitLab users should upgrade to 19.1.8, 19.2.6, or 19.3.2, then review logs and assess whether credentials may have been exposed.
GitLab Patches CVSS 10.0 Vulnerability Allowing Unauthenticated File Reads
Disclaimer: The content provided on Phemex News is for informational purposes only. We do not guarantee the quality, accuracy, or completeness of the information sourced from third-party articles. The content on this page does not constitute financial or investment advice. We strongly encourage you to conduct you own research and consult with a qualified financial advisor before making any investment decisions.
