Brief
GitLab Path Traversal Vulnerability Allows Unauthenticated File Reads
GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability that allows an unauthenticated user to read arbitrary files, according to the National Vulnerability Database.
According to the National Vulnerability Database, GitLab Community Edition and Enterprise Edition contain a path traversal vulnerability. The vulnerability allows an unauthenticated user to read arbitrary files. The cause is improper path confinement and missing authentication enforcement in the repository commits API.
Our reading
Our reading is that this vulnerability could affect any workflow that relies on GitLab's repository commits API, as it may allow unauthorized access to files.
Source details and supporting facts
Each line is stated by the page named above it.
Stated by NIST National Vulnerability Database
- GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability.
- The vulnerability allows an unauthenticated user to read arbitrary files due to improper path confinement and missing authentication enforcement in the repository commits API.
Sources
- NIST National Vulnerability DatabaseText stored 16 September 2026
How this story was checked. Written from the 1 page listed above, stored 16 September 2026; claims checked against that stored text on 16 September 2026.
What that means
- 2 of 2 reported statements were confirmed against the page that carries them; the rest were removed rather than published.
- Figures in the text were required to appear in the stored source text: yes. Identifiers: yes.
- The check reads stored text only: no claim rests on a fresh look that did not happen.
- Where the reporting was silent, the text says so instead of filling the gap.