Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 12 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Sat, 12 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Sat, 12 Sep 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. | |
| Title | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab | |
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2026-09-12T11:08:14.424Z
Reserved: 2026-09-04T14:34:20.856Z
Link: CVE-2026-85706
Updated: 2026-09-12T10:53:26.759Z
Status : Received
Published: 2026-09-12T03:16:30.473
Modified: 2026-09-12T11:16:33.373
Link: CVE-2026-85706
No data.
OpenCVE Enrichment
Updated: 2026-09-12T09:45:11Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')