AI description
CVE-2026-18252 describes a security vulnerability found in GitLab Enterprise Edition (EE) that allows for arbitrary command execution. This flaw is specifically tied to the integration of an AI-driven Claude agent within the Continuous Integration/Continuous Delivery (CI/CD) pipeline infrastructure. The vulnerability arises because the configuration parameters for the Claude agent are processed using input directly from user-controlled sources without adequate sanitization or validation. This oversight enables an authenticated user with developer-role permissions to inject malicious payloads into the configuration stream, thereby manipulating how the agent processes instructions and executing arbitrary commands within the CI context. The affected GitLab EE versions include all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1.
- Description
- GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Primary
- Base score
- 8.1
- Impact score
- 5.2
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
- Severity
- HIGH
- cve@gitlab.com
- CWE-829
- Hype score
- Not currently trending
🚨*CVE* CVE-2026-18252 GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions,… https://t.co/7Y6YVYv7vU ----- Traducción: CVE-2026-18252 Git… https://t.co/bYtskK
@infoflowcloud
30 Aug 2026
35 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-18252 GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions,… https://t.co/qiGVc6dGsk
@CVEnew
30 Aug 2026
1785 Impressions
0 Retweets
0 Likes
2 Bookmarks
0 Replies
0 Quotes
GitLabは19.3.1、19.2.5、19.1.7を公開し、Duo Claude AIエージェントで任意コマンド実行につながる高深刻度の脆弱性「CVE-2026-18252」など複数の問題を修正した。 CVE-2026-18252は、開発者権限を持つ認証済みユーザーが任
@yousukezan
26 Aug 2026
1557 Impressions
2 Retweets
4 Likes
2 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "52CCB423-5677-48F1-AC4B-33B391881922",
"versionEndExcluding": "19.1.7",
"versionStartIncluding": "18.9.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "80975E60-F9E7-41D6-A1CA-384E3CA3964D",
"versionEndExcluding": "19.2.5",
"versionStartIncluding": "19.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:19.3.0:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "99734371-8B08-4207-88EB-D23AE5608E9D",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]