GitLab urged users on Thursday to immediately patch their servers against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825.
The flaw was discovered by a security researcher using the handle s3ntago and reported through GitLab's HackerOne bug bounty program. It results from improper path confinement and missing authentication enforcement in the repository commits API. Under certain conditions, unauthenticated attackers can exploit the flaw to read arbitrary files from vulnerable servers.
GitLab also fixed a critical vulnerability, CVE-2026-87719, caused by an insecure deserialization weakness in the GraphQL subscription serializer. The issue affects GitLab Enterprise Edition and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
The two vulnerabilities were fixed in GitLab Community Edition and Enterprise Edition versions 19.3.2, 19.2.6, and 19.1. GitLab strongly recommends that operators upgrade self-managed installations to one of these versions immediately.
GitLab.com is already running a patched version. GitLab Dedicated customers do not need to take action.
Comments
0No comments yet. Be the first to comment.