The vulnerability, reported by researcher Mohamed Abdelaiz (S3ntago), affects GitLab CE/EE versions 18.7 through 19.1.7, 19.2 through 19.2.5, and 19.3 through 19.3.1. It receives a CVSS score of 10.0, the highest possible severity, because it requires no authentication and only that the targeted GitLab instance have at least one public project.
According to the advisory, "under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API." Exploitation could allow attackers to steal secrets, configuration details, and deploy tokens, potentially compromising CI/CD pipelines and gaining access to other connected systems.
GitLab released a patch on September 11. Within hours, watchTowr reported observing active probes. The US Cybersecurity and Infrastructure Security Agency (CISA) subsequently added the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, signaling that government agencies must patch promptly.
Cybersecurity executive Christopher Houser warned that patching alone is insufficient. "It doesn't revoke the deploy tokens, CI variables, and SSH keys an attacker already copied," he said. "Rotate those, then check which packages and images your builds pulled while the old credentials were still valid."
watchTowr recommends defenders hunt through logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.path parameters to detect exploitation attempts.