First published · Last updated
CVE-2026-85706: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
A path traversal vulnerability in GitLab CE and EE repository commits API allows an unauthenticated user to read arbitrary files. The source instructs applying vendor mitigations and following CISA BOD 26-04 guidance.
Categories: technology
Generated scores
Scores are based on the cited reporting and use a 1–10 scale. Read the methodology.
- Confidence
- 6/10
- Geographic reach
- 5/10
- Global importance
- 3/10
- Impact magnitude
- 4/10
- Positivity
- 2/10
- Urgency
- 7/10
Why it matters
Unauthenticated arbitrary file reads can expose sensitive data from affected GitLab instances.

