A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed

A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed GitLab to 19.2.2, 19.1.4, or 19.0.6. https:// suriq.io/blog/gitlab-package-r egistry-arbitrary-file-write # CVE # infosec # cybersecurity

1 social postother

Claim audit

No BS check run yet — press ⚖ to extract this story's claims and verify them against independent sources.

All coverage

A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed

mastodon:infosec-exchangeother37d ago kagi ↗

A logged-in GitLab user can abuse the package registry to write files across a self-managed server (CVE-2026-10053, CVSS 8.5). A public test lab just proved the flaw is real. Fix: update self-managed GitLab to 19.2.2, 19.1.4, or 19.0.6. https:// suriq.io/blog/gitlab-package-r egistry-arbitrary-file-write # CVE # infosec # cybersecurity