Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5943 articles · 214609 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-18252PATCHED
GitLab · GitLab

Inclusion of Functionality from Untrusted Control Sphere in GitLab

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

Affected Products

VendorProductVersions
GitLabGitLab18.9, 19.2, 19.3

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/607342
  • https://hackerone.com/reports/3863650(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/

Related News (1 articles)

Tier C
VulDB16d ago
CVE-2026-18252 | GitLab up to 19.1.6/19.2.4/19.3.0 Claude Agent permission
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.1.719.2.519.3.1
CWECWE-829
PublishedAug 26, 2026
Last enriched16d ago
Trending Score5
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-85706EXPKEV
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 137
CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 41
CRITICALCVE-2026-87719
Deserialization of Untrusted Data in GitLab
Trending: 41
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 27
HIGHCVE-2026-75871
GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.10 to 19.0.12, 19.1 to 19.1.7, and 19.2 to 19.2.2 that could have allowed an a
Trending: 4

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 26, 2026
Discovered by ZDM
Aug 26, 2026
Patch Available
Aug 27, 2026