GPU VulnDB

Database/Control plane, storage & DevOps

GitLab package registry: authenticated path traversal that can lead to remote code execution

CVE-2026-10053Control plane, storage & DevOpscurated

Impact

An authenticated GitLab user can, under conditions the advisory does not spell out, use a path traversal in the package registry to reach remote code execution on the GitLab instance. For a GPU fleet the blast radius is not the web app: a self-managed GitLab typically holds runner registration tokens, container registry credentials, CI variables with cloud and cluster secrets, and deploy keys that reach the scheduler and the nodes. Code execution there is a route into the pipelines that build and deploy every workload on the fleet. GitLab reports this as remediated across the affected branches; the record does not say it has been seen exploited.

Who can reach it

Any authenticated user of the GitLab instance, including a low-privilege account on an instance that allows self-registration. Network reach to the GitLab web interface is enough; no access to a GPU node is needed.

What to do

Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 depending on your branch - all versions from 18.8 up to those are affected. This is a single-service upgrade and restart on the GitLab host, not a fleet action; no node drain or reboot is involved. GitLab.com is already patched by the vendor. If you cannot upgrade immediately, tighten who can authenticate to the instance and whether new sign-ups are open.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.