CVE-2023-2825 is a critical path traversal vulnerability in GitLab Community Edition and Enterprise Edition 16.0.0. Improper handling of the uploads path permits an unauthenticated remote attacker to read arbitrary files from the GitLab server. Exploitation is possible when an attachment exists in a public project nested within at least five groups. GitLab assigned a CVSS v3.1 score of 10.0.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a single Metasploit auxiliary module: 'gitlab_authenticated_subgroups_file_read.rb'. The module exploits CVE-2023-2825, a directory traversal vulnerability in GitLab version 16.0.0, allowing an authenticated attacker to read arbitrary files from the server as the 'gitlab-www' user. The exploit requires valid credentials for a user who can create projects and groups, and leverages the ability to create deeply nested groups (depth 5-11) to perform the traversal. The module authenticates to the GitLab web interface, creates the necessary group structure, uploads a dummy file, and then crafts a traversal path to read the specified file (default: /etc/passwd). The file contents are saved as loot in Metasploit. Cleanup is performed by deleting the top-level group, which cascades to remove all created objects. The module is operational and provides a working file read exploit for vulnerable GitLab instances.
This repository contains a proof-of-concept (PoC) exploit for CVE-2023-2825, a critical path traversal vulnerability in GitLab CE/EE 16.0.0. The exploit is implemented as a Python script (poc.py) that automates the process of logging into a GitLab instance, creating the required nested group structure (11 groups), creating a public project, uploading a file, and then exploiting the path traversal flaw in the file upload endpoint to read arbitrary files from the server (demonstrated with /etc/passwd). The README.md provides detailed background, exploitation steps, and output examples. The exploit targets the file upload and retrieval endpoints of GitLab, requiring the attacker to have valid credentials and network access to the target instance. The repository is structured with a disclaimer, a comprehensive README, and the main exploit script. No weaponized or framework-based code is present; this is a standalone PoC.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A prior GitLab path-traversal vulnerability that allowed arbitrary file reads and was actively attacked shortly after disclosure.
A historical GitLab critical arbitrary-file-read/path-traversal vulnerability cited as a comparison to CVE-2026-85706. The content states that ransomware gangs and APT groups weaponized it against unpatched servers.
A historical maximum-severity GitLab path-traversal vulnerability that could expose sensitive data on unpatched servers.
Ancienne vulnérabilité GitLab de traversée de répertoires de sévérité maximale, corrigée en mai 2023, qui exposait potentiellement du code source, des identifiants, des jetons et des fichiers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.