Path Traversal Vulnerability in GitLab CE/EE Products
CVE-2026-10053

8.5HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
23 August 2026

Badges

πŸ“ˆ Score: 474πŸ‘Ύ Exploit Exists🟑 Public PoC

What is CVE-2026-10053?

CVE-2026-10053 is a critical vulnerability identified in GitLab's Community Edition (CE) and Enterprise Edition (EE) products. Specifically, it affects versions preceding 19.0.6, 19.1.4, and 19.2.2, allowing authenticated users to exploit a path traversal vulnerability present in the package registry under certain conditions. This vulnerability poses a risk as it could lead to remote code execution (RCE), enabling attackers to gain unauthorized control over systems running the affected GitLab software. As GitLab serves as a platform for repository management and CI/CD, the exploitation of this vulnerability can negatively impact organizations by jeopardizing the integrity and availability of project data, potentially allowing for unauthorized modifications or data extraction.

Potential impact of CVE-2026-10053

  1. Remote Code Execution: The most serious implication of this vulnerability is the potential for remote code execution, where attackers can run arbitrary code on the host server, leading to a full system compromise.

  2. Data Breach Risks: With RCE capabilities, attackers could gain unauthorized access to sensitive data stored within the GitLab instance, including source code, configuration files, and user credentials, heightening the risk of data breaches.

  3. Operational Disruption: The exploitation of this vulnerability may result in significant operational disruptions, as compromised systems may require extensive recovery efforts, including downtime and system restoration, to ensure the integrity and security of data and services.

Affected Version(s)

GitLab 18.8 < 19.0.6

GitLab 19.1 < 19.1.4

GitLab 19.2 < 19.2.2

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • 🟑

    Public PoC available

  • πŸ‘Ύ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [invisiblemeerkat](https://hackerone.com/invisiblemeerkat) for reporting this vulnerability through our HackerOne bug bounty program
.