TL;DR
GitLab recently released versions 19.3.1, 19.2.5, and 19.1.7 to address multiple critical flaws. This GitLab EE security patch resolves a high-severity flaw allowing arbitrary command execution within the Duo Claude AI agent. Administrators must apply these updates to secure their self-managed installations immediately.
Why the Vulnerability Matters
The most critical issue, CVE-2026-18252, scores an 8.7 on the CVSS scale. This flaw permits an authenticated user with developer permissions to execute arbitrary commands. Furthermore, it impacts CI contexts directly. Moreover, a successful attack allows unauthorized users to manipulate the CI system. Many organizations rely heavily on GitLab for their DevOps pipelines. Consequently, a breach here could compromise entire software supply chains. Security teams must prioritize this update to prevent unauthorized code modifications. GitLab has not released specific affected installation counts. However, they strongly recommend that all self-managed instances upgrade immediately. Currently, no reports confirm active exploitation in the wild. A researcher reported this issue privately through HackerOne.
How the Attack Works
The vulnerability stems from improper functionality inclusion from an untrusted control sphere. Specifically, the Claude AI agent processes configurations from a user-controlled source. Therefore, attackers can manipulate these inputs to bypass security boundaries. Consequently, the application interprets the malicious input as legitimate commands. This action triggers command execution within the restricted environment.
Besides the primary command execution vulnerability, the update addresses multiple denial of service flaws. For example, CVE-2026-77801 allows authenticated users to disrupt background job processing. This disruption occurs due to missing object count limits. Additionally, CVE-2025-10903 enables an unbounded loop through specially crafted input in the SCIM user provisioning feature.
Affected Versions and Mitigation
Impacted GitLab Releases
The CVE-2026-18252 flaw affects multiple recent product lines. Specifically, it impacts GitLab EE versions 18.9 through 19.1.6. Additionally, it affects version 19.2 through 19.2.4. Finally, it impacts version 19.3 before 19.3.1.
Patch and Mitigation Steps
The only complete mitigation is to apply the latest GitLab EE security patch. Administrators running self-managed environments must deploy version 19.3.1, 19.2.5, or 19.1.7. GitLab.com and GitLab Dedicated platforms already run these secure versions. For detailed deployment guidance, administrators should review the official patch release GitLab 19.3.1 documentation. As a result, no temporary workarounds exist for this specific arbitrary command execution flaw.
Support Our Threat Intelligence
Find our zero-day alerts and CVE reports helpful? Support our work today and unlock a 100% ad-free reading experience!