CVE-2026-10053
published 2026-08-23CVE-2026-10053: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain…
PriorityP263high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.77%
53.9th percentile
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| gitlab | gitlab | — | — |
| gitlab | gitlab | >= 18.8 < 19.0.6 | 19.0.6 |
| gitlab | gitlab | >= 18.8.0 < 19.0.6 | 19.0.6 |
| gitlab | gitlab | >= 19.1 < 19.1.4 | 19.1.4 |
| gitlab | gitlab | >= 19.1.0 < 19.1.4 | 19.1.4 |
| gitlab | gitlab | >= 19.2 < 19.2.2 | 19.2.2 |
| gitlab | gitlab | >= 19.2.0 < 19.2.2 | 19.2.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
GitLab up to 19.0.5/19.1.3/19.2.1 Package Registry path traversal (Nessus ID 339039)
vuldb·2026-08-23·CVSS 8.5
CVE-2026-10053 [HIGH] GitLab up to 19.0.5/19.1.3/19.2.1 Package Registry path traversal (Nessus ID 339039)
A vulnerability, which was classified as critical, was found in GitLab up to 19.0.5/19.1.3/19.2.1. Affected is an unknown function of the component Package Registry. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-10053. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.
GHSA
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authentica
ghsa_unreviewed·2026-08-23
CVE-2026-10053 [HIGH] CWE-22 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authentica
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
GitLab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
vendor_gitlab·2026-08-23·CVSS 8.5
CVE-2026-10053 [HIGH] CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.
Affected products: GitLab
Affected versions: >=18.8, =19.1, =19.2, <19.2.2 (affected)
Solution: Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.
Credit: Thanks [invisiblemeerkat](https://hackerone.com/invisiblemeerkat) for reporting this vulnerability through our HackerOne bug bounty program
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-23
Published