Back to all lessons
Awareness Lessons
last month

GitLab Path Traversal Flaw Actively Exploited — CISA Adds to KEV Catalog

A path traversal vulnerability (CVE-2026-85706) in GitLab Community and Enterprise Editions has been confirmed as actively exploited in the wild, prompting CISA to add it to its Known Exploited Vulnerabilities Catalog. Path traversal flaws allow attackers to access files and directories outside the intended scope, potentially exposing source code, credentials, and sensitive configuration files stored in GitLab repositories. The inclusion in the KEV Catalog triggers mandatory remediation timelines for federal agencies under BOD 26-04, underscoring the critical importance of risk-based vulnerability prioritization. Organizations that delay patching internet-facing developer tools like GitLab face significant risk of data theft and supply chain compromise. This incident highlights the danger of treating developer platforms as lower-priority assets despite their access to sensitive intellectual property and infrastructure secrets.

Tactical Insight

Immediate actions

  • Apply the latest GitLab security patch or upgrade to a non-vulnerable version without delay.
  • Audit GitLab instances for signs of exploitation, including unexpected file access patterns or unauthorized repository access.
  • Restrict public internet exposure of GitLab instances using firewall rules or VPN-gated access where operationally feasible.

Long-term improvements

  • Maintain a continuously updated inventory of all internet-facing assets, including developer tools and code repositories.
  • Implement a formal, risk-based vulnerability management program that prioritizes CISA KEV entries for accelerated remediation.
  • Establish emergency patching procedures with defined SLAs for critically exploited vulnerabilities (e.g., 24–72 hours for KEV-listed flaws).

Detection measures

  • Enable detailed access and audit logging within GitLab to detect anomalous file traversal or unauthorized data access attempts.
  • Integrate GitLab logs with your SIEM platform to trigger alerts on suspicious path traversal patterns or API abuse.
  • Deploy vulnerability scanning tools configured to flag EOL or unpatched versions of GitLab across your environment.