Skip to content
GitLabCVE-2026-10053

GitLab: remote code execution

High8.5CVE-2026-10053 · Published Aug 23, 2026 · updated Aug 31, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 18.8, < 19.0.619.0.6
>= 19.1, < 19.1.419.1.4
>= 19.2, < 19.2.219.2.2
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-22

More GitLab advisories

All GitLab
Advisory
GitLab: improper authorization
Low3.5Aug 26
GitLab: denial of service
Medium6.5Aug 26
GitLab: improper authorization
Medium5.5Aug 26
GitLab: untrusted functionality included
High7.3Aug 26
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1...
Medium4.3Aug 26
GitLab: denial of service
Medium6.5Aug 26

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.