CVE-2021-22192 is a vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), affecting all versions starting from 13.2. The flaw allows authenticated users, who are otherwise unauthorized for such actions, to execute arbitrary code on the GitLab server. The vulnerability is likely due to improper input validation or insufficient access control in a component that processes user-supplied data, leading to remote code execution (RCE).
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository provides a comprehensive lab environment for demonstrating and exploiting CVE-2021-22192, a critical unauthenticated remote code execution vulnerability in GitLab EE 13.2.0. The structure includes Docker-based setup scripts for GitLab, a runner, and a license cracker, as well as helper scripts for key generation, runner registration, and environment management (in both Bash and PowerShell). The README.md offers detailed step-by-step instructions for setting up the environment, generating a cracked license, registering a runner, and performing the exploit. The exploit leverages the ability to upload a Ruby payload as a snippet, then abuses the kramdown wiki rendering process by referencing the uploaded file in a specially crafted wiki page. This causes the server to execute arbitrary Ruby code, resulting in remote code execution as demonstrated by the creation of a file on the server. The repository also includes a test directory with the kramdown library and related files, but these are for debugging and are not directly part of the exploit chain. Key endpoints include the local GitLab web interface, license upload and runner registration pages, and the file paths used for payload delivery and post-exploitation verification. The attack vector is network-based, targeting the web interface of a vulnerable GitLab instance. The exploit is a proof-of-concept, requiring manual steps but demonstrating a full unauthenticated RCE chain.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.