HackMyIP
← Back to News
2026-09-14 Dark Reading

GitLab CVE-2026-85706: CVSS 10.0 Path Traversal Threatens Supply Chains

VulnerabilitySupply Chain

A maximum-severity vulnerability in GitLab is putting software supply chains worldwide at imminent risk. Tracked as CVE-2026-85706, the flaw is a path traversal vulnerability carrying a CVSS score of 10.0—the highest possible rating on the vulnerability severity scale. It affects both GitLab Community Edition (CE) and Enterprise Edition (EE) instances, leaving self-hosted DevOps pipelines exposed to remote exploitation in default configurations.

The vulnerability allows an attacker to read or write arbitrary files outside the intended working directory of a GitLab instance, effectively bypassing repository access controls. Researchers warn that successful exploitation could enable attackers to inject malicious code into repositories, steal source code secrets, or pivot into CI/CD runners to compromise downstream software builds. Because GitLab is deeply embedded in continuous integration and deployment pipelines, a single compromised instance can cascade into dozens or hundreds of tainted software releases—a textbook supply chain attack scenario. The flaw was responsibly disclosed and patched in GitLab's latest security release, and administrators are urged to update immediately.

Security teams should prioritize patching their self-hosted GitLab servers and audit access logs for signs of exploitation, including unusual file reads or writes outside repository paths. Organizations running internet-exposed GitLab instances can use a port scanner to confirm whether their deployment is publicly reachable and review firewall rules accordingly. Developers and admins should also rotate any credentials, tokens, or SSH keys stored within affected GitLab instances—verifying them against known breaches via a password checker is a sensible first step. With a CVSS 10.0 rating and active exploitation risk, this is one of the most urgent GitLab advisories in recent memory and warrants immediate action across every affected deployment.

Source: Dark Reading →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →