Arbitrary Command Execution in GitLab EE Affects Multiple Versions
CVE-2026-18252

7.3HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-18252?

An issue in GitLab EE allows an authenticated user with developer-role permissions to execute arbitrary commands in a CI context. This vulnerability arises when the Claude agent processes configuration from a user-controlled source, potentially leading to unauthorized command execution. Users of the affected versions should upgrade to the latest patches to mitigate this risk.

Affected Version(s)

GitLab 18.9 < 19.1.7

GitLab 19.2 < 19.2.5

GitLab 19.3 < 19.3.1

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [thwin_htet](https://hackerone.com/thwin_htet) for reporting this vulnerability through our HackerOne bug bounty program
.