GitLab Repository Commits API Vulnerability: Critical Severity
- Severity
- CRITICAL
- CVSS
- 10
- Affected component
- gitlab (npm)
- Patched version
- Not yet available
A critical severity vulnerability in GitLab's repository commits API allows unauthenticated users to read arbitrary files from the server. This vulnerability has been actively exploited in the wild.
What happened
A critical security vulnerability, tracked as CVE-2026-85706, has been confirmed in GitLab's repository commits API. This flaw allows unauthenticated users to read arbitrary files from the server, posing a significant risk to data confidentiality. The vulnerability was first flagged on September 11, 2026, and confirmed on September 12, 2026. It has been actively exploited in the wild shortly after public disclosure.
The vulnerability affects the gitlab (npm) package, though no authoritative version range has been published yet. Users are advised to upgrade to the latest version of GitLab and monitor for any unauthorized file access. The National Cyber Security Centre (NCSC) and multiple GitHub Security Advisories have confirmed the vulnerability and provided recommendations for mitigation.
What to do about it
- Upgrade to the latest version of GitLab immediately.
- Monitor your GitLab instance for any unauthorized file access.
- Consult the primary sources for the most up-to-date information and recommendations.
- No official fix has been published yet for the affected gitlab (npm) package. Monitor the sources below for updates.
How 0Day would have caught this
gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using the gitlab (npm) package, you may be affected. No authoritative version range has been published yet.
What should I do right now?
Upgrade to the latest version of GitLab and monitor for any unauthorized file access.
Has this been exploited in the wild?
Yes, this vulnerability has been actively exploited in the wild.
Sources
- NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions
- [GHSA-2h44-8472-frjj] @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
- [GHSA-vmp7-252j-cwp7] @zereight/mcp-gitlab: DNS rebinding reaches local Streamable HTTP MCP transport
- [GHSA-2h44-8472-frjj] @zereight/mcp-gitlab Vulnerable to Server-Side Request Forgery
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- CISA: Hackers now exploit max severity GitLab flaw in attacks
- Maximum Severity GitLab Flaw Puts Supply Chains at Risk
- GitLab Vulnerability Exploited One Day After Disclosure