A security update has been released to address a vulnerability in GitLab products.
The vulnerability is a remote code execution vulnerability (a vulnerability that allows arbitrary code to be executed remotely) caused by a path traversal ( where file paths deviate to unintended locations) in the GitLab CE/EE Package Registry, known as CVE-2026-10053.
The affected versions of GitLab CE/EE are within the following ranges:
18.8 Or higher but lower than 19.0.6.
19.1 Or higher but lower than 19.1.4.
19.2 Or higher but lower than 19.2.2.
Vulnerability Patches are available for versions 19.0.6, 19.1.4, And 19.2.2.
Users of these products should update to the latest version of the Vulnerability Patch following the instructions on the reference site.