NPM · SEPTEMBER 2026 · CONFIRMED

GitLab Repository Commits API Vulnerability: Critical Severity

Severity
CRITICAL
CVSS
10
Affected component
gitlab (npm)
Patched version
Not yet available
CVE-2026-85706

A critical severity vulnerability in GitLab's repository commits API allows unauthenticated users to read arbitrary files from the server. This vulnerability has been actively exploited in the wild.

What happened

A critical security vulnerability, tracked as CVE-2026-85706, has been confirmed in GitLab's repository commits API. This flaw allows unauthenticated users to read arbitrary files from the server, posing a significant risk to data confidentiality. The vulnerability was first flagged on September 11, 2026, and confirmed on September 12, 2026. It has been actively exploited in the wild shortly after public disclosure.

The vulnerability affects the gitlab (npm) package, though no authoritative version range has been published yet. Users are advised to upgrade to the latest version of GitLab and monitor for any unauthorized file access. The National Cyber Security Centre (NCSC) and multiple GitHub Security Advisories have confirmed the vulnerability and provided recommendations for mitigation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If gitlab is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using the gitlab (npm) package, you may be affected. No authoritative version range has been published yet.

What should I do right now?

Upgrade to the latest version of GitLab and monitor for any unauthorized file access.

Has this been exploited in the wild?

Yes, this vulnerability has been actively exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats