Find notable cyber news and cases, enriched with sources, timelines, and signals.

GitLab repository commits API path traversal vulnerability (CVE-2023-2825)

Vulnerability
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

GitLab has a maximum-severity path traversal vulnerability, CVE-2023-2825, that can let unauthenticated attackers read arbitrary files from vulnerable servers under certain conditions. The flaw affects the repository commits API and exposes GitLab Community Edition (CE) and Enterprise Edition (EE) deployments until they are patched. GitLab says self-managed installations should upgrade immediately because fixed builds are now available.

Related Happenings

GitLab self-managed installations immediate upgrade advisory

Advisory/Mitigation
H score37 First: 11.09.2026 14:15 Last: 11.09.2026 14:15 Sources 1

How related: "These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately," the company warned on Thursday.

About this happening: GitLab issued immediate upgrade guidance for self-managed GitLab installations after fixing two security issues in GitLab CE and GitLab EE. Operators were told...

GitLab notebook diff authenticated RCE flaw

Vulnerability
H score37 First: 25.07.2026 11:34 Last: 25.07.2026 11:34 Sources 1

About this happening: A public PoC exploit now shows an authenticated RCE path in GitLab that can run commands as git on vulnerable self-managed servers. The flaw affects GitLab CE/EE...

Oj parser state corruption and ASLR leak analysis in the GitLab notebook diff exploit chain

Technical Analysis
H score23 First: 25.07.2026 11:34 Last: 25.07.2026 11:34 Sources 1

About this happening: Researchers published deep exploit analysis of Oj parser bugs in GitLab's notebook diff path, showing how callback-pointer corruption and a heap-address leak can b...

GitLab CE/EE SSRF flaw (CVE-2021-39935)

Vulnerability
H score1 First: 04.02.2026 17:42 Last: 04.02.2026 17:42 Sources 1

About this happening: GitLab CE/EE CVE-2021-39935 is an actively exploited SSRF flaw that lets unauthenticated external users make server-side requests through the CI Lint API. The...

Timeline

  1. 11.09.2026 14:15 1 articles · 1h ago

    Security researcher reports GitLab repository commits API path traversal flaw

    Initial Disclosure

    Security researcher s3ntago reported CVE-2023-2825 through GitLab's HackerOne bug bounty program after identifying improper path confinement and missing authentication enforcement in the repository commits API, a flaw that could let unauthenticated attackers read arbitrary files from vulnerable GitLab servers under certain conditions.

    Show sources
  2. 11.09.2026 14:15 2 articles · 1h ago

    GitLab releases patched CE and EE builds for two critical vulnerabilities

    Mitigation Patch Update

    GitLab released fixed builds for GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.3.2, 19.2.6, and 19.1 to address CVE-2023-2825 and CVE-2026-87719, warned self-managed installations to upgrade immediately, said GitLab.com is already running the patched version, and noted GitLab Dedicated customers do not need to take action.

    Show sources