{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2026-85706",
  "revision": 1,
  "title": "GitLab — Unauthenticated arbitrary file read via commits endpoint",
  "summary": "A path traversal flaw in GitLab's repository commits endpoint, combined with missing authentication checks, lets an unauthenticated attacker read arbitrary files from the GitLab server. Affects 18.7 and later before 19.1.8, 19.2.6 and 19.3.2.",
  "source_type": "cve",
  "severity": "critical",
  "cvss": {
    "score": 10,
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N",
    "version": "3.1"
  },
  "epss": 0.14563,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2026-09-11",
    "prerequisites": "Network access to the GitLab web service; no account or user interaction needed"
  },
  "remediation": {
    "patch_available": true,
    "fixed_in": [
      "GitLab >= 19.1.8",
      "GitLab >= 19.2.6",
      "GitLab >= 19.3.2"
    ]
  },
  "mitre_attack": [
    "T1190",
    "T1083"
  ],
  "kill_chain": "initial_access",
  "recommended_action": "Upgrade GitLab to 19.1.8, 19.2.6 or 19.3.2 now; restrict internet exposure of the instance until patched and review logs for unauthenticated commits requests.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2026-85706",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
      "retrieved_at": "2026-09-20T10:52:56.734Z",
      "confidence": "high",
      "extractor": "claude-code"
    },
    {
      "fields": [
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
      "retrieved_at": "2026-09-20T11:09:51.520Z",
      "confidence": "high",
      "extractor": "human"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-85706",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "writeup",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-85706"
    }
  ],
  "published_at": "2026-09-12T03:16:30.473Z",
  "issued_at": "2026-09-20T10:52:56.734Z",
  "tags": [
    "gitlab",
    "path-traversal",
    "arbitrary-file-read",
    "missing-authentication"
  ]
}
