Arbitrary Command Execution in GitLab EE Affects Multiple Versions
CVE-2026-18252
7.3HIGH
What is CVE-2026-18252?
An issue in GitLab EE allows an authenticated user with developer-role permissions to execute arbitrary commands in a CI context. This vulnerability arises when the Claude agent processes configuration from a user-controlled source, potentially leading to unauthorized command execution. Users of the affected versions should upgrade to the latest patches to mitigate this risk.
Affected Version(s)
GitLab 18.9 < 19.1.7
GitLab 19.2 < 19.2.5
GitLab 19.3 < 19.3.1
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [thwin_htet](https://hackerone.com/thwin_htet) for reporting this vulnerability through our HackerOne bug bounty program