Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196341 vulns · 36/41 feeds (7d)
← Back to list
8.5
CVE-2026-10053PATCHED
gitlab · gitlab

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

Affected Products

VendorProductVersions
gitlabgitlab18.8, 19.1, 19.2

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/601596
  • https://hackerone.com/reports/3754194(technical-description, exploit, permissions-required)

Related News (1 articles)

Tier C
VulDB23h ago
CVE-2026-10053 | GitLab up to 19.0.5/19.1.3/19.2.1 Package Registry path traversal
→ No new info (linked only)
CVSS 3.18.5 HIGH
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.0.619.1.419.2.2
CWECWE-22
PublishedAug 23, 2026
Trending Score25
Source articles1
Independent1
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 70
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 34
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13
MEDIUMCVE-2026-4879
Missing Authorization in GitLab
Trending: 13
HIGHCVE-2026-15217
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 13

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 23, 2026
Patch Available
Aug 23, 2026
Discovered by ZDM
Aug 23, 2026