đš CRITICAL GITLAB EXPLOIT ALERT đš
CVE-2026-85706 dropped with a perfect 10.0 CVSS score. This is as bad as it gets.
đŽ What's broken:
Path traversal vuln in $GITLAB CE/EE lets UNAUTHENTICATED attackers read ANY file from your server via Repository Commits API. No login needed. Full server access.
â ïž Versions at risk:
âą 18.7 â 19.1.7
âą 19.2 â 19.2.5
âą 19.3 â 19.3.1
đ ïž Fix NOW:
Upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately. Then audit your logs and rotate ALL credentials.
If you're running self-managed GitLab and haven't patched, assume you're already compromised. This is actively exploitable.
Not a drill. Patch or get rekt.
CVE-2026-85706 dropped with a perfect 10.0 CVSS score. This is as bad as it gets.
đŽ What's broken:
Path traversal vuln in $GITLAB CE/EE lets UNAUTHENTICATED attackers read ANY file from your server via Repository Commits API. No login needed. Full server access.
â ïž Versions at risk:
âą 18.7 â 19.1.7
âą 19.2 â 19.2.5
âą 19.3 â 19.3.1
đ ïž Fix NOW:
Upgrade to 19.1.8, 19.2.6, or 19.3.2 immediately. Then audit your logs and rotate ALL credentials.
If you're running self-managed GitLab and haven't patched, assume you're already compromised. This is actively exploitable.
Not a drill. Patch or get rekt.