Skip to main content Skip to local navigation

GitLab Path Traversal Vulnerability (CVE-2026-85706)

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed vulnerability (CVE-2026-85706) affects GitLab Community Edition (CE) and Enterprise Edition (EE) and may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, and other sensitive information.

Severity level:
CVSS Score: 10/Critical.

Description:

CVE-2026-85706 is a critical path traversal vulnerability in GitLab's Repository Commits API. The flaw results from improper path confinement and missing authentication enforcement, allowing an unauthenticated attacker to submit a specially crafted request and read arbitrary files from the GitLab server. Sensitive information such as SSH keys, credentials, configuration files, CI/CD secrets, and access tokens may be exposed.

Affected Versions:

  • GitLab CE/EE 18.7 through 19.1.7
  • GitLab CE/EE 19.2.0 through 19.2.5
  • GitLab CE/EE 19.3.0 through 19.3.1


Impact:

Successful exploitation may allow attackers to read arbitrary files from the GitLab server.

Resolution:
Upgrade GitLab immediately to the following fixed versions:-

  • GitLab 19.1.8
  • GitLab 19.2.6
  • GitLab 19.3.2

 

Reference:

https://www.cve.org/CVERecord?id=CVE-2026-85706

https://www.cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706

https://socprime.com/blog/cve-2026-85706-critical-gitlab-path-traversal-flaw/

 

UIT Information Security




Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web 

 

 

 

GitLab Path Traversal Vulnerability (CVE-2026-85706)

 

A picture containing text  Description automatically generated

 

Information Security Advisory


A recently disclosed vulnerability (CVE-2026-85706) affects GitLab Community Edition (CE) and Enterprise Edition (EE) and may allow an unauthenticated remote attacker to read arbitrary files from the GitLab server, potentially exposing credentials, secrets, and other sensitive information.

Severity level:
CVSS Score: 10/Critical.

Description:

CVE-2026-85706 is a critical path traversal vulnerability in GitLab's Repository Commits API. The flaw results from improper path confinement and missing authentication enforcement, allowing an unauthenticated attacker to submit a specially crafted request and read arbitrary files from the GitLab server. Sensitive information such as SSH keys, credentials, configuration files, CI/CD secrets, and access tokens may be exposed.

Affected Versions:

  • GitLab CE/EE 18.7 through 19.1.7
  • GitLab CE/EE 19.2.0 through 19.2.5
  • GitLab CE/EE 19.3.0 through 19.3.1


Impact:

Successful exploitation may allow attackers to read arbitrary files from the GitLab server.

Resolution:
Upgrade GitLab immediately to the following fixed versions:-

  • GitLab 19.1.8
  • GitLab 19.2.6
  • GitLab 19.3.2

 

Reference:

https://www.cve.org/CVERecord?id=CVE-2026-85706

https://www.cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-2-released/

https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706

https://socprime.com/blog/cve-2026-85706-critical-gitlab-path-traversal-flaw/

 

UIT Information Security




Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web