Intel

AIKIDO-2026-643299

gitlab-ce is vulnerable to Path Traversal

Path TraversalCVE-2026-85706 Published 4 days ago

100

Critical Risk

This Affects:

OSgitlab-ce
18.7.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

The repository commits API fails to confine requested paths and to enforce authentication in some cases. An unauthenticated attacker can read arbitrary files from the GitLab server through that API. The fix confines commit API paths and enforces authentication so arbitrary file reads are no longer possible.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gitlab-ce is vulnerable to Path Traversal in versions 18.7.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform