Executive brief
GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability in the package registry component that allows authenticated users to execute arbitrary code on the server. An attacker with valid credentials could exploit this flaw to compromise the integrity of the entire GitLab instance and access sensitive project data.
Technical details
The vulnerability is a path traversal flaw in GitLab's package registry that permits authenticated users to achieve remote code execution (RCE). The vulnerability affects GitLab CE/EE versions 18.8 through 19.0.5, 19.1 through 19.1.3, and 19.2 through 19.2.1. The attack requires valid authentication credentials and exploits improper input validation in the package registry component. Patches are available in GitLab 19.0.6, 19.1.4, and 19.2.2 or later.
Affected products
- GitLab GitLab CE 18.8 before 19.0.6, 19.1 before 19.1.4, 19.2 before 19.2.2
- GitLab GitLab EE 18.8 before 19.0.6, 19.1 before 19.1.4, 19.2 before 19.2.2
Timeline
- 2026-08-23: disclosed: Vulnerability published to NVD
- 2026-08-23: patched: Patches available in GitLab 19.0.6, 19.1.4, 19.2.2