Количество 3
Количество 3
CVE-2026-18252
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
GHSA-gjcp-3p8v-jvrw
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
BDU:2026-12783
Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с включением функций из недостоверной контролируемой области, позволяюзая нарушителю выполнить произвольный код
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-18252 GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source. | CVSS3: 7.3 | 0% Низкий | 26 дней назад | |
GHSA-gjcp-3p8v-jvrw GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source. | CVSS3: 7.3 | 0% Низкий | 26 дней назад | |
BDU:2026-12783 Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с включением функций из недостоверной контролируемой области, позволяюзая нарушителю выполнить произвольный код | CVSS3: 7.3 | 0% Низкий | 26 дней назад |
Уязвимостей на страницу