Impact
GitLab has a path traversal flaw in its repository commits API that, under certain conditions, allows an unauthenticated user to read arbitrary files from the server. The flaw arises from improper pathname limitation and the lack of authentication enforcement, enabling attackers to construct file paths that escape the intended restricted directory and access any file on the GitLab instance. This omission permits the disclosure of sensitive data such as configuration files, credentials, or codebases without requiring credentials.
Affected Systems
The vulnerability affects GitLab Community Edition and Enterprise Edition from version 18.7 up through all intermediate 18.x releases, through 19.0 before 19.0.9, and extends to 19.1.x before 19.1.8, 19.2.x before 19.2.6 and 19.3.x before 19.3.2. Any GitLab installation running a version in these ranges is susceptible.
Risk and Exploitability
The CVSS score of 10 reflects the severity of this data exposure and the high impact on confidentiality. An EPSS score of 93% indicates that the vulnerability is highly likely to be exploited in the wild. It is catalogued in the CISA KEV list, underscoring its known exploitation risk. Attackers would target the public repository commits API endpoint, sending specially crafted requests that bypass directory restrictions to retrieve arbitrary files. No authentication is required, so the attack vector is broad and generally low in technical barrier.
OpenCVE Enrichment