CVE-2026-18252: GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3
Summary
GitLab EE (Enterprise Edition, a version of the GitLab code management platform with extra features) had a security flaw where authenticated users with developer-role permissions could run arbitrary commands (any code they wanted) in a CI context (continuous integration, the automated testing and deployment process) because a Claude agent was reading configuration from user-controlled sources without proper validation. GitLab has now fixed this issue.
Solution / Mitigation
Update to GitLab EE version 19.1.7, 19.2.5, or 19.3.1 or later, depending on which version you are currently running.
Vulnerability Details
7.3(high)
EPSS: 0.0%
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
network
low
low
required
August 26, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-18252
First tracked: August 26, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 92%