Executive brief
GitLab has fixed a security issue where the code shown in the web browser could differ from the code actually downloaded by a user. An attacker with basic account access could create a repository that tricks other users into downloading different files than what they reviewed on the website. This could lead to the accidental deployment or execution of unvetted code.
Technical details
An ambiguity reference issue exists in GitLab CE/EE due to improper handling of Git reference name resolution (CWE-706). An authenticated attacker can create a repository with specifically named tags or branches that cause the GitLab web UI to display different file contents than what is retrieved during a 'git clone' or download operation. This requires minimal privileges (PR:L) and some user interaction (UI:R) to view or download the malicious repository. The vulnerability affects versions 16.5 through 18.11.7, 19.0.x before 19.0.4, and 19.1.x before 19.1.2. Patches are available in versions 18.11.7, 19.0.4, and 19.1.2.
Affected products
- GitLab GitLab Community Edition (CE) 16.5 to 18.11.7, 19.0 to 19.0.4, 19.1 to 19.1.2
- GitLab GitLab Enterprise Edition (EE) 16.5 to 18.11.7, 19.0 to 19.0.4, 19.1 to 19.1.2
Timeline
- 2026-07-08: patched: GitLab released versions 19.1.2, 19.0.4, and 18.11.7.
- 2026-07-08: advisory