The path traversal vulnerability, discovered by a security researcher known as 's3ntago' and reported through GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. GitLab described the bug as a maximum-severity issue. The second flaw, CVE-2026-87719, affects GitLab EE only and allows authenticated users with Duo Chat access to steal sensitive credentials and Advanced Search instance configurations.
'These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately,' the company warned. GitLab.com is already running the patched version, and GitLab Dedicated customers are not affected.
GitLab has a history of similar high-severity vulnerabilities. In May 2023, it addressed another maximum-severity path traversal flaw (CVE-2023-2825) that exposed sensitive data including proprietary software code and credentials. In 2024, CISA and the FBI urged software developers to eliminate path traversal vulnerabilities before shipping, calling such flaws 'unforgivable.' More recently, in January, GitLab patched a high-severity two-factor authentication bypass. Since November 2021, CISA has flagged four GitLab vulnerabilities as exploited in attacks.