CVE-2024-9164Active Exploitation(gitlab / gitlab)

MEDIUMCVSS 8.8 · HIGH

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for gitlab gitlab systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.

5.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-306

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Peaked 1d ago at 1 mentions (2026-08-21); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-21: 1Mentions · 2026-09-11: 1PoC Mentioned / Linked · 2026-08-21: 1Active Exploitation · 2026-08-21: 1Active Exploitation · 2026-09-11: 1Technical Details · 2026-08-21: 1Technical Details · 2026-09-11: 108-2109-11
Signal classification1 categories
Active Exploitation
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2024-9164, a CVSS 8.8 path traversal flaw in GitLab's commits API to read arbitrary server files without authentication. Within hours, they escalated privileges using stolen credentials from config files and moved laterally across CI/CD environments. Runtime segmentation helps limit blast radius when DevOps platforms are compromised. #CloudSecurity #DevSecOps 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/gitlab-cve-2026-85706-cvss-10-file-read-flaw-draws-in-wild-probes

    Post summary

    The excerpt reports that CVE-2024-9164, a path traversal flaw in GitLab’s commits API, has been actively exploited to read server files, elevate privileges using stolen config credentials, and move laterally across CI/CD environments, with no patch or PoC details provided.

    0000054
    2.0K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows attackers exploited CVE-2024-9164 to inject code through GitLab's GraphQL API, escalating from unauthenticated access to repository destruction within hours. This incident highlights how development infrastructure compromises can enable lateral movement into connected CI/CD and cloud environments. #DevSecOps 🔗 Full breakdown: https://aviatrix.ai/threat-research-center/gitlab-cve-2026-19478-code-injection-active-exploitation

    Post summary

    The post confirms attackers actively exploited GitLab's CVE-2024-9164 via GraphQL API code injection, escalating from unauthenticated access to repository destruction, and provides a link to a detailed breakdown.

    0000062
    1.9K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more