GitLab Updates Fix Arbitrary Command Execution Vulnerability
ID: cd607c26-cb82-57ad-98df-99d83380e366
STIX ID: report--cd607c26-cb82-57ad-98df-99d83380e366
Feed Name: securityonline.info
Threat Score
GitLab released emergency security updates (19.3.1, 19.2.5, 19.1.7) to fix multiple critical flaws—most notably CVE-2026-18252 (CVSS 8.7)—that allow an authenticated developer to execute arbitrary commands via the Duo Claude AI agent and affect CI contexts; administrators of self-managed instances are urged to patch immediately, as the vulnerability could compromise DevOps pipelines and software supply chains, though no active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
