Impact
GitLab Enterprise Edition has a flaw that allows an authenticated developer to cause the system to execute arbitrary commands within a CI job. The issue arises when the GitLab Claude agent processes pipeline configuration supplied from a user‑controlled source, enabling the attacker to inject commands that run with the CI job runner’s privileges. The vulnerability is a form of remote code execution and is classified as CWE‑829, reflecting code execution through trusted input.
Affected Systems
The misconfiguration exists in GitLab EE releases prior to 19.1.7, 19.2.5, and 19.3.1, as well as all 18.x releases from 18.9 and earlier. Any GitLab host running one of these affected versions and allowing developer‑level users to create or modify CI pipelines is exposed. The advisory applies to all installations of the affected Enterprise Edition releases.
Risk and Exploitability
The CVSS score is 7.3, indicating a high severity. EPSS data is not available, so the likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation has been detected to date. Exploitation requires an authenticated developer with access to CI configuration; therefore internal actors who can modify pipelines pose the greatest risk.
OpenCVE Enrichment