๐จ SlowMist TI Alert: CVE-2026-85706 ๐จ
๐ด A critical path traversal vulnerability in
@gitlab CE/EE (CVSS 10.0) could allow unauthenticated attackers to read arbitrary files from affected GitLab servers via the Repository Commits API.
๐ ๏ธ GitLab has released security patches to address this vulnerability.
โ ๏ธ Affected:
affected from 18.7 before 19.1.8
affected from 19.2 before 19.2.6
affected from 19.3 before 19.3.2
๐จ Self-managed GitLab users should upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately, and review logs and potentially exposed credentials after patching.
๐ Stay alert and keep your infrastructure up to date.
๐