Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Published: 2026-08-26
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

GitLab Enterprise Edition has a flaw that allows an authenticated developer to cause the system to execute arbitrary commands within a CI job. The issue arises when the GitLab Claude agent processes pipeline configuration supplied from a user‑controlled source, enabling the attacker to inject commands that run with the CI job runner’s privileges. The vulnerability is a form of remote code execution and is classified as CWE‑829, reflecting code execution through trusted input.

Affected Systems

The misconfiguration exists in GitLab EE releases prior to 19.1.7, 19.2.5, and 19.3.1, as well as all 18.x releases from 18.9 and earlier. Any GitLab host running one of these affected versions and allowing developer‑level users to create or modify CI pipelines is exposed. The advisory applies to all installations of the affected Enterprise Edition releases.

Risk and Exploitability

The CVSS score is 7.3, indicating a high severity. EPSS data is not available, so the likelihood of exploitation cannot be precisely quantified. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread public exploitation has been detected to date. Exploitation requires an authenticated developer with access to CI configuration; therefore internal actors who can modify pipelines pose the greatest risk.

Generated by OpenCVE AI on August 26, 2026 at 14:37 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.7, 19.2.5, 19.3.1 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab Enterprise Edition to v19.1.7, v19.2.5, v19.3.1 or newer to remove the flaw.
  • If an upgrade cannot be performed immediately, temporarily revoke developer privileges for modifying CI pipeline configuration or disable pipeline creation for those users.
  • Audit all existing CI configuration files for user‑supplied parameters, sanitize any malicious content, and verify that no executable logic remains that could be abused before resuming normal operations.

Generated by OpenCVE AI on August 26, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 13:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Title Inclusion of Functionality from Untrusted Control Sphere in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-829
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-27T03:57:14.567Z

Reserved: 2026-07-29T15:34:54.723Z

Link: CVE-2026-18252

cve-icon Vulnrichment

Updated: 2026-08-26T15:39:31.927Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-26T14:17:08.000

Modified: 2026-08-31T15:42:04.433

Link: CVE-2026-18252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T14:45:04Z

Weaknesses
  • CWE-829

    Inclusion of Functionality from Untrusted Control Sphere