⚠️CVE-2026-85706 (CVSS 10.0)⚠️

Your GitLab will hand a stranger its files. 😱

No login. No account. An attacker just URL-encodes one letter of commits → %63ommits, and GitLab-Workhorse waves the request through — so a single unauthenticated POST to the repository commits API reads files straight off the server filesystem. Config, internal logs, source paths, versions… all without ever signing in.

Already in CISA KEV — exploited in the wild. 🚨

If you self-host GitLab, patch to 19.1.8 / 19.2.6 / 19.3.2 now.

🔥PoC + setup: github.com/EQSTLab/CVE-20…

#GitLab #ArbitraryFileRead #CVE #PoC #Exploit #CyberSecurity #CVE_2026_85706