GITLAB has released urgent security patches (versions 19.3.1, 19.2.5, and 19.1.7) to address several critical vulnerabilities, particularly CVE-2026-18252. This flaw, scoring 8.7 on the CVSS scale, allows authenticated users with developer permissions to execute arbitrary commands, potentially compromising software supply chains. The patches address deficiencies in the Claude AI agent's input processing. Other vulnerabilities, including denial of service issues, are also fixed. All administrators running self-managed environments are advised to apply these updates immediately, as no active exploitation has been reported yet.
GitLab Updates Fix Arbitrary Command Execution Vulnerability
CyberSIXT Evidence Panel
Article by CyberSIXT