GitLab CE/EE authenticated RCE via path traversal in package registry
GitLab CE/EE 18.8 through 19.2 allow an authenticated user to achieve RCE via path traversal in the package registry. Fixed in 19.0.6, 19.1.4, 19.2.2.
- Vendor
- GitLab
- Product
- GitLab CE/EE (self-managed, versions 18.8 – 19.2)
- CVSS
- 8.5
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
GitLab CE/EE contains a path traversal vulnerability in the package registry component that, under certain conditions, allows an authenticated user to achieve remote code execution on the server. The flaw does not require administrator privileges — any account holder on a self-managed instance is within the attack surface.
Affected versions: All GitLab CE/EE self-managed releases from 18.8 up to (not including) the following patched versions:
- 19.0.6
- 19.1.4
- 19.2.2
GitLab.com is already patched. This only affects self-managed deployments.
Remediation: Upgrade to the patched release that corresponds to your current minor version track. See GitLab’s security release page for upgrade guides and full advisory details.
Source: NVD entry · GitLab issue tracker
