GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.
References
| Link | Resource |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/work_items/627748 | Broken Link |
| https://hackerone.com/reports/3909881 | Permissions Required |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-09-12 03:16
Updated : 2026-09-14 14:22
NVD link : CVE-2026-85706
Mitre link : CVE-2026-85706
CVE.ORG link : CVE-2026-85706
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
