Home / Sep 13, 2026 / Story
0
#3 SecurityWeek general September 11, 2026 at 16:11 UTC

GitLab Vulnerability Exploited One Day After Disclosure

By Ionut Arghire

AI Summary

A critical-severity path traversal vulnerability in GitLab (CVE-2023-2825) — allowing unauthenticated attackers to read arbitrary files from the server — was exploited within one day of public disclosure, with internet-wide scanning already detected. GitLab has urged operators of all self-managed installations to upgrade immediately. The speed of exploitation underscores the narrow patching window for critical GitLab flaws affecting potentially thousands of self-hosted instances.

Relevance score: 86.0/100

# More from September 13