
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-18252 is a remote code execution vulnerability in GitLab Enterprise Edition (EE) affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1. The flaw allows an authenticated user with developer-role permissions to execute arbitrary commands in a CI context under certain conditions, due to the Claude AI agent processing configuration from a user-controlled source. It was published on August 26, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-829 (Inclusion of Functionality from Untrusted Control Sphere), where the Claude AI agent integrated into GitLab EE processes pipeline or agent configuration sourced from user-controlled input without sufficient validation or sandboxing. An authenticated attacker with at least developer-level permissions can craft a malicious configuration that the Claude agent executes, resulting in arbitrary command execution within the CI pipeline context. Exploitation requires user interaction (e.g., triggering a pipeline run) and network access, but attack complexity is low once the preconditions are met. The vulnerability was originally reported via HackerOne report #3863650 (GitHub Advisory, GitLab Issue).
Successful exploitation allows an authenticated developer-role user to execute arbitrary commands within the CI/CD pipeline environment, resulting in high confidentiality and integrity impact — including potential exposure of CI secrets, environment variables, tokens, and source code, as well as the ability to tamper with build artifacts or pipeline outputs. Availability is not directly impacted. The CI context may provide access to sensitive credentials (e.g., deployment keys, cloud provider tokens) that could enable lateral movement into downstream infrastructure (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is 0.0, indicating a currently low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is not automatable and requires an authenticated user with developer-role permissions plus user interaction, limiting the attack surface to trusted insiders or compromised developer accounts.
.gitlab-ci.yml) or Claude agent configuration within the project to include malicious commands or directives that the Claude agent will process as executable instructions..gitlab-ci.yml; Claude agent logs showing configuration loaded from unusual or user-supplied paths.curl, wget, env, printenv, data exfiltration commands); unexpected access to CI environment variables or secrets within job output.GitLab has released patched versions addressing this vulnerability: 19.1.7, 19.2.5, and 19.3.1. All GitLab EE users running affected versions (18.9 through 19.3.0) should upgrade immediately to one of these fixed releases (GitLab Patch Release). As interim mitigations, administrators should restrict developer-role permissions to trusted users only, enforce mandatory code review for pipeline configuration changes, and monitor CI execution logs for suspicious command activity. Disabling or restricting the Claude agent feature until patching is complete may also reduce exposure.
Security news outlet SecurityOnline.info covered the GitLab EE security patch shortly after disclosure. The vulnerability was also tracked by VulDB and ENISA's EUVD (EUVD-2026-66428). No notable researcher commentary or significant social media discussion has been identified beyond standard vulnerability tracking and advisory coverage (SecurityOnline).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."