importantSYS.SOURCE: The Hacker News• 2026-09-11T22:00:18+05:30
Critical GitLab Path Traversal Vulnerability (CVE-2026-85706) Exploited in Real-World Attacks
A critical path traversal vulnerability (CVE-2026-85706) in GitLab allows unauthenticated file reads with a CVSS score of 10.0, already targeted in real-world attacks. Patches are urgently recommended for affected versions to prevent exploitation of sensitive data and CI/CD pipelines.
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.
The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
*** END OF TRANSMISSION ***