Skip to content

CVE lookup

CVE-2026-85706

Pruva has a verified reproduction for CVE-2026-85706: GitLab CE/EE unauthenticated path traversal in Repository Commits API leads to arbitrary file read. The canonical evidence record is REPRO-2026-00354.

REPRO

REPRO-2026-00354

Package

Unknown

Severity

CRITICAL

Status

published