LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-18252

gitlab · gitlab

Published
CVSS7.3
Severityhigh
WeaknessCWE-829
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-18252

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-18252.