Wire · technology
GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 12 September 2026 · Fusion42 review
GitLab disclosed a critical CVSS 10.0 path traversal vulnerability in its repository commits API allowing unauthenticated file-read access, with active in-the-wild probes detected hours after public disclosure. Multiple GitLab CE and EE versions are affected, and the vulnerability enables attackers to extract sensitive configuration files and credentials.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Developer Tools, and 2 sources have reported it.
◆ ◆ The Wire takeaway
GitLab's critical file-read flaw changes your security posture overnight. You must patch immediately or risk your users’ data being quietly stolen by attackers exploiting this deep system weakness.
◆ Coverage
2 sources · 12 Sep 2026
◆ Related on Wire
◆ Topics