Tag: path traversal flaw
1 article

GitLab Discloses Path Traversal Flaw Exploited in Wild
GitLab has revealed a critical path traversal flaw, CVE-2026-85706, that allows unauthenticated users to access sensitive files on its servers, and security researchers have already spotted attackers probing for vulnerabilities in the wild. This maximum-severity bug, scoring a CVSS 10.0, enables hackers to read arbitrary files, including log files and configuration files.