GPU VulnDB

Database/Control plane, storage & DevOps

GitLab EE: developer-role user can run arbitrary commands in CI via attacker-controlled agent config

CVE-2026-18252Control plane, storage & DevOpscurated

Impact

An account with only Developer permissions can get arbitrary commands executed in a CI context, because the Claude agent integration consumes configuration from a source the user controls. CI runners on a GPU fleet are rarely low-value targets: they commonly execute on or beside the accelerator nodes with the container toolkit mounted, and they hold registry push credentials and cluster tokens used to promote images into the serving path. The record notes the attack requires user interaction, so this is not a fully unattended path. GitLab reports confidentiality and integrity impact, not availability.

Who can reach it

An authenticated GitLab user holding Developer role on the target project, on an instance where the Claude agent CI integration is in use. Requires the user interaction the vendor records in the vector (UI:R).

What to do

Upgrade self-managed GitLab EE to 19.1.7, 19.2.5, or 19.3.1 (or later) per the patch release notes; all versions from 18.9 up to those are affected. This is a GitLab application upgrade and service restart, with no impact on runner nodes or GPU hosts. GitLab.com is already patched. If you cannot upgrade promptly, the described precondition is the agent integration itself, so disabling it removes the exposure.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.