GitLab released CE and EE versions 19.3.1, 19.2.5, and 19.1.7 to remediate seven security vulnerabilities, led by CVE-2026-18252 (CVSS 8.7). The flaw lets an authenticated GitLab EE user with Developer privileges execute arbitrary commands in CI contexts by abusing user-controlled configuration processed by the GitLab Duo Claude AI agent. Affected EE releases span 18.9 through 19.1.6, 19.2 through 19.2.4, and 19.3 prior to 19.3.1; no workaround is available.
The patches also resolve authenticated denial-of-service issues involving background-job processing and SCIM provisioning, plus authorization and access-control weaknesses. GitLab.com and GitLab Dedicated are already patched, while self-managed customers should upgrade immediately; single-node deployments should plan for downtime while database migrations complete, whereas correctly configured multi-node deployments can use zero-downtime upgrade procedures. No exploitation of CVE-2026-18252 has been publicly confirmed.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
GitLab released CE and EE versions 19.3.1, 19.2.5, and 19.1.7, remediating seven vulnerabilities, including CVE-2026-18252, which could let an authenticated EE Developer execute arbitrary commands in a CI context via user-controlled Duo Claude AI agent configuration. The release also fixed denial-of-service and authorization flaws; GitLab urged self-managed customers to upgrade, while GitLab.com was already patched and GitLab Dedicated required no action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
7 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcesecurityonline.info
Open sourcedocs.gitlab.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcecommunity.tenable.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.