Skip to finding
important · Edge — GitLab

Attackers are exploiting GitLab's unauthenticated commit endpoint to read arbitrary server files.

Affects

GitLab Community Edition and Enterprise Edition, self-managed source-code and CI/CD servers.

A crafted commit request reaches File.read without authentication, and malformed percent encoding reflects the selected file through error handling.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 13, 2026