Skip to content

Critical path traversal GitLab bug hit in the wild

Around 40,000 self-hosted versions of GitLab may still be at risk as CISA flags exploitation.

Critical path traversal GitLab bug hit in the wild
Image Credit: https://unsplash.com/@pankajpatel

A critical bug in software forge GitLab that allows unauthenticated users to access arbitrary files is already being exploited in the wild, just days after it was first disclosed by the company.

The CVSS 10-rated path traversal issue, tracked as CVE-2026-85706, was patched by GitLab on 10 September but could still be present in self-hosted versions of the forge that have not been updated.

Security company watchTowr said on Friday that it had already seen behavioural probes for the vulnerability against its honeypot network, meaning public-facing instances were already at risk.

The researchers warned: “In practical terms, an attacker with no credentials could send a request to the commits API and have the application return the contents of files it should never have exposed, potentially including configuration files, secrets, or other sensitive server-side data.”

Research by Cycode Labs in 2025 found there were at least 40,000 public GitLab servers.

Two critical bugs

This content is for members only

Subscribe
Add The Stack on Google