FR
live
tag

#gitlab

GitLab 19.3.2 closes an unauthenticated arbitrary file read and seventeen more flaws

GitLab shipped versions 19.3.2, 19.2.6 and 19.1.8 on September 10, 2026 to fix eighteen flaws, including an unauthenticated arbitrary file read through the commits API and an insecure deserialization scored CVSS 9.9. Every exposed self-managed instance must be updated without delay, and protected CI/CD variable secrets need a review.

GitLab patches CVE-2026-18252, command execution via the Duo Claude agent in CI

On August 26, 2026, GitLab shipped a fix for CVE-2026-18252, a flaw in the Duo Claude AI agent that lets an authenticated developer execute arbitrary commands in a CI context through user-controlled configuration. The lesson goes beyond GitLab: an AI agent wired into CI is a new execution surface, and the configuration it consumes is now part of the security boundary.

GitLab patches a critical unauthenticated GraphQL code injection flaw (CVSS 9.4)

On August 18, 2026, GitLab released fixes for two vulnerabilities, including a critical code injection via a GraphQL directive (CVE-2026-19478, CVSS 9.4) exploitable remotely without authentication or user interaction, allowing attackers to modify or delete public projects. Every self-managed installation must upgrade immediately — GitLab.com and GitLab Dedicated are already patched.

Type at least two characters.

navigate open esc dismiss