GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
highDetails
A critical path traversal vulnerability in the repository commits API allows an unauthenticated attacker to read arbitrary files from a targeted GitLab server. The flaw is being actively probed and exploited in the wild, beginning just one day after public disclosure.
Affected Systems
GitLab Community Edition (CE) and Enterprise Edition (EE).
Potential Impact
An attacker can exfiltrate sensitive data, including configuration files, credentials, and source code, leading to a full system compromise.
Mitigations
Immediately patch all GitLab servers. This vulnerability is on the CISA KEV list with a required remediation date of 2026-09-14.