CVE-2026-85706 is a CVSS 10.0 path traversal vulnerability in the GitLab Repository Commits API affecting self-managed GitLab Community Edition and Enterprise Edition. Improper path confinement, combined with missing authentication enforcement under certain conditions, allows traversal sequences in crafted HTTP GET requests to escape the intended repository directory and retrieve arbitrary files readable by the GitLab service process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This two-file repository is a Docker-based proof of concept for CVE-2026-85706 affecting GitLab Community Edition 19.3.1-ce.0. docker-compose.yml deploys the vulnerable gitlab/gitlab-ce:19.3.1-ce.0 image as container gitlab-vuln and exposes its HTTP service on localhost:8085; its comment identifies 19.3.2-ce.0 as the remediation test version. README.md provides the complete validation workflow: start the container, create a canary at /tmp/canary.txt, then submit one of two crafted POST requests to the project-1 repository commits endpoint. The variants use a .json endpoint suffix with JSON data or a trailing slash with form data, each passing an absolute path in file.path. There is no standalone exploit program, reverse shell, persistence mechanism, or framework integration; the repository is an operationally reproducible LFI/file-disclosure PoC using curl commands and Docker configuration.
30 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A CVSS 10.0 unauthenticated path traversal vulnerability in self-managed GitLab CE and EE that permits arbitrary file reads from the GitLab host. Exposed secrets and database credentials could enable GitLab administrative compromise, CI/CD supply-chain tampering, and broader network pivoting.
A maximum-severity GitLab repository commits API path-traversal flaw caused by improper path confinement and missing authentication enforcement, enabling unauthenticated arbitrary-file reads under certain conditions.
Critical unauthenticated path-traversal vulnerability in GitLab's repository commits API. Improper path confinement and missing authentication enforcement can permit arbitrary file reads, potentially exposing application settings, tokens, SSH keys, database credentials, and other files readable by the GitLab process.
A critical unauthenticated path traversal and missing-authentication flaw in the GitLab repository commits API that permits arbitrary file reads, potentially exposing application settings, secrets, tokens, SSH keys, and database credentials.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.