Database/Control plane, storage & DevOps
GitLab package registry: authenticated path traversal that can lead to remote code execution
Impact
An authenticated GitLab user can, under conditions the advisory does not spell out, use a path traversal in the package registry to reach remote code execution on the GitLab instance. For a GPU fleet the blast radius is not the web app: a self-managed GitLab typically holds runner registration tokens, container registry credentials, CI variables with cloud and cluster secrets, and deploy keys that reach the scheduler and the nodes. Code execution there is a route into the pipelines that build and deploy every workload on the fleet. GitLab reports this as remediated across the affected branches; the record does not say it has been seen exploited.
Who can reach it
Any authenticated user of the GitLab instance, including a low-privilege account on an instance that allows self-registration. Network reach to the GitLab web interface is enough; no access to a GPU node is needed.
What to do
Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 depending on your branch - all versions from 18.8 up to those are affected. This is a single-service upgrade and restart on the GitLab host, not a fleet action; no node drain or reboot is involved. GitLab.com is already patched by the vendor. If you cannot upgrade immediately, tighten who can authenticate to the instance and whether new sign-ups are open.
References
Related entries
- GitLab: developer-role user can run pipelines on a protected branch without push rightsCVE-2026-15423 · GitLab CE/EE (CI/CD pipeline reference authorization)High
- GitLab EE: authenticated user can attribute AI usage to another namespaceCVE-2026-19228 · GitLab EE (AI feature usage attribution / request identity authorization)High
- open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handling: Three related defectsCVE-2026-44944 · open-iscsi / open-isns - iscsiuio control socket authorization and iSNS record handlingHigh
- GitLab EE: developer-level user can run a policy test pipeline and read protected CI/CD variablesCVE-2026-79708 · GitLab EE (security policy test pipelines, CI/CD variable scope validation)High
- GitLab EE: crafted project export import overflows the Advanced Search Unicode buffer for RCECVE-2026-88765 · GitLab EE (Advanced Search indexing, Unicode conversion buffer on project import)High
- Renovate: unescaped Gradle distributionUrl gives a repository command execution as the Renovate userCVE-2026-88886 · Renovate self-hosted (Gradle Wrapper manager, distributionUrl)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.