CVE-2026-18252 HIGH

CVE-2026-18252: Inclusion of Functionality from Untrusted Control Sphere in GitLab

Vendor Gitlab
Product GitLab
Weakness CWE-829 · Inclusion from untrusted sphere
Published August 26, 2026
Last update August 27, 2026

CVSS base score

7.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N

What the vulnerability does

01Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.

Key dates

02Disclosure timeline

August 26, 2026 CVE published
August 27, 2026 Record updated