Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-93577: GitLab could let logged-in user run code
CVE-2026-93577 · published 16 days ago
Summary
A flaw in GitLab's build pipeline processing could let someone who is signed in upload a specially crafted script and cause the server to run unwanted code. This affects all versions before the latest patches for the 19.2, 19.3, and 19.4 series. Apply the newest GitLab updates as soon as possible to close the gap.
What to do
- Update gitlab to version 19.4.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | gitlab | gitlab |
< 19.2.7 >= 19.2.0, < 19.2.7 >= 19.3.0, < 19.3.3 19.4.0 |
| Bitnami | – | gitlab |
>= 19.4.0, < 19.4.1 Fix: upgrade to 19.4.1
|
Original advisory text
Integer Overflow or Wraparound in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
References
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-4-1-released/ Release Notes Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/629758 Issue Tracking
- https://hackerone.com/reports/3995696 Permissions Required
- https://nvd.nist.gov/vuln/detail/CVE-2026-93577 URL
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-190Integer Overflow
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Track software like this
Free during beta