GitLab fixes critical path-traversal flaw after rapid in-the-wild probes

TL;DR Summary
GitLab released patches for a critical path-traversal flaw (CVE-2026-85706, CVSS 10) in the repository commits API that could let an unauthenticated attacker read arbitrary server files; in-the-wild probes were observed within hours of disclosure. The fixes also address a high-severity insecure deserialization issue in GitLab EE (CVE-2026-87719). Admins should upgrade to patched versions (CE/EE 19.1.8, 19.2.6, 19.3.2) or limit internet exposure, and monitor for suspicious POST requests to /api/v4/projects/{id}/repository/commits/ containing file.Path parameters to identify exploitation attempts.
Topics:technology#cve-2026-85706#gitlab#path-traversal#security#unauthenticated-access#vulnerability
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure The Hacker News
- GitLab urges users to patch max severity path traversal flaw BleepingComputer
- Rapid Reaction: GitLab Path Traversal Vulnerability (CVE-2026-85706) watchTowr
- GitLab Patches Critical Flaws Enabling Arbitrary File Read, Credential Theft and Remote Code Execution cyberpress.org
- GitLab fixes critical vulnerability as internet-wide probing begins Field Effect
Reading Insights
Total Reads
0
Unique Readers
0
Time Saved
2 min
vs 3 min read
Condensed
82%
426 → 76 words
Want the full story? Read the original article
Read on The Hacker News