CVE-2026-18252

Published Aug 26, 2026

Last updated 4 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-18252 describes a security vulnerability found in GitLab Enterprise Edition (EE) that allows for arbitrary command execution. This flaw is specifically tied to the integration of an AI-driven Claude agent within the Continuous Integration/Continuous Delivery (CI/CD) pipeline infrastructure. The vulnerability arises because the configuration parameters for the Claude agent are processed using input directly from user-controlled sources without adequate sanitization or validation. This oversight enables an authenticated user with developer-role permissions to inject malicious payloads into the configuration stream, thereby manipulating how the agent processes instructions and executing arbitrary commands within the CI context. The affected GitLab EE versions include all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1.

Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Source
cve@gitlab.com
NVD status
Analyzed
Products
gitlab

Risk scores

CVSS 3.1

Type
Primary
Base score
8.1
Impact score
5.2
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Severity
HIGH

Weaknesses

cve@gitlab.com
CWE-829

Social media

Hype score
Not currently trending

Configurations