Path Traversal Vulnerability in GitLab CE/EE Products
CVE-2026-10053
Key Information:
Badges
What is CVE-2026-10053?
CVE-2026-10053 is a critical vulnerability identified in GitLab's Community Edition (CE) and Enterprise Edition (EE) products. Specifically, it affects versions preceding 19.0.6, 19.1.4, and 19.2.2, allowing authenticated users to exploit a path traversal vulnerability present in the package registry under certain conditions. This vulnerability poses a risk as it could lead to remote code execution (RCE), enabling attackers to gain unauthorized control over systems running the affected GitLab software. As GitLab serves as a platform for repository management and CI/CD, the exploitation of this vulnerability can negatively impact organizations by jeopardizing the integrity and availability of project data, potentially allowing for unauthorized modifications or data extraction.
Potential impact of CVE-2026-10053
-
Remote Code Execution: The most serious implication of this vulnerability is the potential for remote code execution, where attackers can run arbitrary code on the host server, leading to a full system compromise.
-
Data Breach Risks: With RCE capabilities, attackers could gain unauthorized access to sensitive data stored within the GitLab instance, including source code, configuration files, and user credentials, heightening the risk of data breaches.
-
Operational Disruption: The exploitation of this vulnerability may result in significant operational disruptions, as compromised systems may require extensive recovery efforts, including downtime and system restoration, to ensure the integrity and security of data and services.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 18.8 < 19.0.6
GitLab 19.1 < 19.1.4
GitLab 19.2 < 19.2.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved