CVE-2026-10053Patch(gitlab / gitlab)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch gitlab gitlab systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to achieve remote code execution due to a path traversal vulnerability in the package registry.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-22

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 5 signals
  • Peaked 2d ago at 4 mentions (2026-08-23); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-08-23: 4Mentions · 2026-08-27: 1Mentions · 2026-09-10: 1PoC Mentioned / Linked · 2026-08-23: 1Exploit Tool / Code · 2026-08-23: 1Patch / Workaround · 2026-08-23: 3Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-10: 1Technical Details · 2026-08-23: 3Technical Details · 2026-08-27: 1Technical Details · 2026-09-10: 108-2308-2709-10
Signal classification2 categories
Patch
583.3%
PoC
116.7%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-08-234
Patch3PoC1
2026-08-271
Patch1
2026-09-101
Patch1
Full discourse6 posts
  • Nicolas Krassas@Dinosn
    PoC

    Reproducible lab for CVE-2026-10053 (GitLab npm package-registry path traversal -> arbitrary file write as git). https://github.com/dinosn/CVE-2026-10053-lab

    Post summary

    A reproducible lab demonstrating CVE-2026-10053 is available, with linked code that shows how the path traversal leads to arbitrary file write. No evidence of active exploitation, patches, or false positive claims is present.

    17056206.5K
    162.1K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Path traversal vulnerability in #GitLab CE/EE can lead to Remote Code Execution #RCE! CVE-2026-10053 CVSS: 8.5. An authenticated user with low privileges can execute code via the package registry. https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/ #Patch #Patch #Patch

    Post summary

    The post alerts to CVE‑2026‑10053, outlining its technical details and a patch, but offers no PoC, exploit code or evidence of active exploitation.

    01022488
    7.3K followersView on X
  • HackProve@hackprove_
    Patch

    【Vulnerability Disclosure | CVE Spotlight】 🚨GitLab Path Traversal Vulnerability Could Lead to Remote Code Execution (CVE-2026-10053) GitLab has addressed a path traversal vulnerability in the Package Registry that could allow an authenticated user to achieve remote code execution (RCE) under certain conditions. 🔍Affected Versions: 18.8 ≤ version < 19.0.6 19.1 ≤ version < 19.1.4 19.2 ≤ version < 19.2.2 🛡️ Mitigation Upgrade immediately to: GitLab 19.0.6 GitLab 19.1.4 GitLab 19.2.2 Or a later supported security release If an immediate upgrade is not possible: Restrict Package Registry upload permissions and API access. Temporarily disable the Package Registry if it is not required for business operations. Review recent package uploads for suspicious activity, unexpected files, and unusual processes launched by GitLab service accounts. 🔐 If you’re running an affected GitLab version, prioritize patching and review your environment for potential exploitation. #CyberSecurity #GitLab #CVE #Vulnerability #AppSec #RCE #BugBounty #InfoSec

    Post summary

    The post discloses GitLab CVE‑2026‑10053, a path traversal flaw that can enable remote code execution for authenticated users, lists affected releases, and urges immediate upgrades or restrictive measures.

    00001111
    1.5K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - GitLab CE/EE authenticated RCE via package registry path traversal (CVE-2026-10053) Path traversal in the package registry that under certain conditions lets an authenticated user achieve remote code execution on the instance. Scope-changed, high attack complexity. Self-managed only — http://GitLab.com and Dedicated are already patched. 👉Affected: GitLab CE/EE 18.8 – <19.0.6, 19.1 – <19.1.4, 19.2 – <19.2.2 | Upgrade to 19.2.2 / 19.1.4 / 19.0.6

    Post summary

    The text warns of an authenticated RCE in GitLab CE/EE via package registry path traversal (CVE‑2026‑10053) and directs users to upgrade to the patched versions or else the vulnerability remains. It focuses mainly on patch guidance.

    00010118
    294 followersView on X
  • ADK Cyber@ADKCyber
    Patch

    GitLab patched CVE-2026-10053 (CVSS 8.5) in CE/EE. Update 18.8+ to 19.0.6, 19.1+ to 19.1.4, or 19.2+ to 19.2.2 immediately. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/B6HxTX9jWd

    Post summary

    GitLab has published patches requiring immediate upgrades to mitigate CVE-2026-10053; no exploitation details or PoC are discussed.

    0000037
    93 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-10053 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain condition… https://www.cve.org/CVERecord?id=CVE-2026-10053

    Post summary

    GitLab has issued a remediation for CVE-2026-10053 affecting multiple major versions; no exploit details or PoC are provided.

    000001.0K
    58.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more