Database/Control plane, storage & DevOps
GitLab EE: developer-role user can run arbitrary commands in CI via attacker-controlled agent config
Impact
An account with only Developer permissions can get arbitrary commands executed in a CI context, because the Claude agent integration consumes configuration from a source the user controls. CI runners on a GPU fleet are rarely low-value targets: they commonly execute on or beside the accelerator nodes with the container toolkit mounted, and they hold registry push credentials and cluster tokens used to promote images into the serving path. The record notes the attack requires user interaction, so this is not a fully unattended path. GitLab reports confidentiality and integrity impact, not availability.
Who can reach it
An authenticated GitLab user holding Developer role on the target project, on an instance where the Claude agent CI integration is in use. Requires the user interaction the vendor records in the vector (UI:R).
What to do
Upgrade self-managed GitLab EE to 19.1.7, 19.2.5, or 19.3.1 (or later) per the patch release notes; all versions from 18.9 up to those are affected. This is a GitLab application upgrade and service restart, with no impact on runner nodes or GPU hosts. GitLab.com is already patched. If you cannot upgrade promptly, the described precondition is the agent integration itself, so disabling it removes the exposure.
References
Related entries
- Apache Airflow 3.3.0: Dag author reaches arbitrary imports in the scheduler via next_kwargs deserializationCVE-2026-67260 · Apache Airflow scheduler (awaiting_input sweep, next_kwargs deserialization)High
- HPE iLO4 / iLO5: Remote code execution on the management controllerCVE-2018-7078 · HPE iLO4 / iLO5High
- HPE iLO3/4/5: Arbitrary code execution on the iLOCVE-2018-7105 · HPE iLO3/4/5High
- NetApp ONTAP Select Deploy administration utility (privilege escalation): An administrative user of the Deploy utilityCVE-2019-17272 · NetApp ONTAP Select Deploy administration utility (privilege escalation)High
- Ceph MON (CephX authentication): The monitor does not sanitize other_keys when handling CEPHX_GET_AUTH_SESSION_KEY, soCVE-2021-20288 · Ceph MON (CephX authentication)High
- AMD PSP1 Configuration Block (APCB) parsing: An out-of-bounds memory write while the platform processes the AMD PSP1CVE-2021-26344 · AMD PSP1 Configuration Block (APCB) parsingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.