PT-2026-79764 · Gitlab · Gitlab Ce/Ee+1

CVE-2026-10053

·

Published

2026-08-23

·

Updated

2026-08-31

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.8 through 19.0.5 GitLab CE/EE versions 19.1 through 19.1.3 GitLab CE/EE versions 19.2 through 19.2.1
Description An authenticated user can achieve remote code execution due to a path traversal flaw in the package registry. Path traversal is a vulnerability that allows an attacker to access files and directories that are stored outside the web root folder by manipulating variables that control a file path. Under specific conditions, this allows a user to write malicious files to sensitive server locations and execute arbitrary commands, potentially exposing all code, secrets, and data within the environment.
Recommendations Update GitLab CE/EE versions 18.8 through 19.0.5 to version 19.0.6. Update GitLab CE/EE versions 19.1 through 19.1.3 to version 19.1.4. Update GitLab CE/EE versions 19.2 through 19.2.1 to version 19.2.2. Restrict access to the package registry as a temporary mitigation measure.

Exploit

Fix

DoS

RCE

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2026-10053
CVE-2026-10053

Affected Products

Gitlab
Gitlab Ce/Ee