GitLab urges users to patch max severity path traversal flaw
PatchGitLab CEGitLab EEOur summary
GitLab has released urgent security updates for its Community Edition and Enterprise Edition platforms to address a maximum-severity path traversal vulnerability identified as CVE-2026-85706. This flaw, located in the repository commits API, lacks proper path confinement and authentication controls, potentially enabling unauthenticated attackers to read arbitrary files from affected servers under specific conditions.
Simultaneously, the vendor addressed a second critical issue, CVE-2026-87719, involving insecure deserialization in the GraphQL subscription serializer that could expose sensitive credentials to authenticated users with Duo Chat access. Administrators are advised to upgrade self-managed installations to versions 19.3.2, 19.2.6, or 19.1 immediately to mitigate these risks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.