Junglewise Threat Intelligence

CVE-2026-10053: GitLab path traversal in package registry

CVE-2026-10053 · Severity: high · CVSS 8.5 · Published 2026-08-23

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability in the package registry component that allows authenticated users to execute arbitrary code on the server. An attacker with valid credentials could exploit this flaw to compromise the integrity of the entire GitLab instance and access sensitive project data.

Technical details

The vulnerability is a path traversal flaw in GitLab's package registry that permits authenticated users to achieve remote code execution (RCE). The vulnerability affects GitLab CE/EE versions 18.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. The attack requires valid authentication credentials and exploits improper input validation in the package registry component. Patches are available in GitLab 19.0.6, 19.1.4, and 19.2.2 or later.

Affected products

  • GitLab GitLab CE 18.8 before 19.0.6, 19.1 before 19.1.4, 19.2 before 19.2.2
  • GitLab GitLab EE 18.8 before 19.0.6, 19.1 before 19.1.4, 19.2 before 19.2.2

Timeline

  • 2026-08-23: disclosed: Vulnerability published to NVD
  • 2026-08-23: patched: Patches available in GitLab 19.0.6, 19.1.4, 19.2.2

References

Related threats