Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-93577: GitLab could let logged-in user run code

CVE-2026-93577 · published 16 days ago
Summary

A flaw in GitLab's build pipeline processing could let someone who is signed in upload a specially crafted script and cause the server to run unwanted code. This affects all versions before the latest patches for the 19.2, 19.3, and 19.4 series. Apply the newest GitLab updates as soon as possible to close the gap.

What to do
  • Update gitlab to version 19.4.1.
Affected software
Ecosystem VendorProductAffected versions
– gitlab gitlab < 19.2.7
>= 19.2.0, < 19.2.7
>= 19.3.0, < 19.3.3
19.4.0
Bitnami – gitlab >= 19.4.0, < 19.4.1
Fix: upgrade to 19.4.1
Original advisory text
Integer Overflow or Wraparound in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer overflow issue when compiling a specially crafted regular expression in a CI/CD configuration.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.9 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-190Integer Overflow
Timeline
Published24 Sep 2026
Updated9 Oct 2026
First seen23 Sep 2026
Sources
CVE-2026-93577 · MITRE
Track software like this
Free during beta