Threat intelligence dashboard
CVE-2026-88765high

Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to overflow the Unicode conversion buffer used in Advanced Search indexing.

Risk score

8.5

CVSS 3.1

Vendor
GitLab
Product
GitLab
CWE
CWE-77
Published
Sep 15, 2026
Updated
Sep 16, 2026
CISA KEV
Not flagged

Affected products and versions

GitLab

GitLab

Version / rangeStatusType
12.3 to before 19.1.8affectedsemver
19.2 to before 19.2.6affectedsemver
19.3 to before 19.3.2affectedsemver

Technical metrics

8.5

CVSS 3.1

Severity
high
Source
GitLab
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H