← Back

Wire · technology

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Published

12 September 2026

Topic

technology

Sectors

CybersecurityDeveloper Tools

Source

Read at thehackernews.com

Verified

Fusion42 · 12 September 2026 · Fusion42 review

GitLab disclosed a critical CVSS 10.0 path traversal vulnerability in its repository commits API allowing unauthenticated file-read access, with active in-the-wild probes detected hours after public disclosure. Multiple GitLab CE and EE versions are affected, and the vulnerability enables attackers to extract sensitive configuration files and credentials.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools, and 2 sources have reported it.

◆ The Wire takeaway

GitLab's critical file-read flaw changes your security posture overnight. You must patch immediately or risk your users’ data being quietly stolen by attackers exploiting this deep system weakness.

Coverage

2 sources · 12 Sep 2026

Related on Wire

Topics

CybersecurityDeveloper Toolsgitlabsecurity-flawcvss-10file-readin-the-wild-probespatch-required