GitLab patched a maximum-severity vulnerability that could allow an unauthenticated attacker to read arbitrary files from a self-managed server. CISA added the flaw to its Known Exploited ...
Threat actors started exploiting CVE-2026-85706, a critical-severity path traversal in GitLab, one day after public ...
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and ...
Attackers are actively targeting a recently patched vulnerability in the popular DevSecOps platform GitLab that they can ...
The vulnerability impacts self-managed CE and EE instances and provides an unauthenticated path to arbitrary file reads. It’s ...
A single HTTP POST to the commits API bypasses all security controls and reads arbitrary files from a GitLab server. CISA ...
An indirect prompt injection flaw in GitLab's artificial intelligence (AI) assistant could have allowed attackers to steal source code, direct victims to malicious websites, and more. In fact, ...
Marketers promote AI-assisted developer tools as workhorses that are essential for today’s software engineer. Developer platform GitLab, for instance, claims its Duo chatbot can “instantly generate a ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results