

Affected Environment
GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1.
Threat Overview
A critical path traversal flaw, CVE-2026-85706, is actively exploited to read arbitrary server files.
Exposure Timeline
Disclosed and remediated 11 September 2026; active exploitation already confirmed in the wild now.
Attack Surface
The repository commits API endpoint, reachable by unauthenticated remote attackers over the network.
Technical Root Cause
Improper path confinement combined with missing authentication enforcement in the commits API.
Exploitation Pathway
Attacker sends a crafted HTTP POST request containing a file.path parameter to read files.
Operational Impact
Unauthenticated attackers can read arbitrary files from vulnerable GitLab servers, exposing sensitive data.
Strategic Impact
Critical for all entities given GitLab's widespread use for source control and CI/CD pipelines.
Required Mitigation
Upgrade GitLab CE/EE to a fixed release beyond the affected version ranges immediately.
Incident Response Guidance
Check for HTTP POST requests to the repository commits API containing file.path parameters.
References
CISA, The Hacker News, GitHub proof-of-concept repository.
Trusted by clients worldwide






Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.




