GitLab disclosed a critical path traversal vulnerability in the repository commits API affecting GitLab Community Edition and Enterprise Edition.
Tracked as CVE-2026-85706, the flaw could allow an unauthenticated attacker to read arbitrary files from a GitLab server when path confinement and authentication enforcement failed under certain conditions. Exposed files could contain sensitive configuration data and credentials.
GitLab rated the issue CVSS 10.0 and released fixes in versions 19.1.8, 19.2.6 and 19.3.2. The company said GitLab.com and GitLab Dedicated infrastructure had already been patched.
GitLab also published threat detections for suspected exploitation attempts and said the vulnerability had been added to CISA's Known Exploited Vulnerabilities catalog. The disclosure raised concerns for organizations using self-managed GitLab in software development and supply-chain environments.