Skip to content
Threat Feed

Vendor

GitLab

16 briefs RSS
low advisory

Multiple Vulnerabilities in GitLab

Multiple security vulnerabilities identified in GitLab CE and EE versions 19.x can result in remote denial of service, data confidentiality breaches, and reflected cross-site scripting.

GitLab Community Edition +1 vulnerability gitlab patch-management
5c
high advisory

electron-updater Vulnerability Leaks Credentials on Cross-Origin Redirects

A vulnerability, CVE-2026-54673, in `electron-builder`'s `builder-util-runtime` package, specifically in its HTTP redirect handler, allows credential headers like `PRIVATE-TOKEN` (GitLab personal access tokens) and mixed-case `Authorization` tokens to be improperly forwarded to attacker-controlled cross-origin redirect destinations, resulting in credential disclosure and enabling unauthorized access to private GitLab resources.

builder-util-runtime < 9.7.0 +2 credential-access exfiltration vulnerability electron software-supply-chain gitlab
2t 1c
critical advisory

Denying the Worm: Detecting SANDWORM_MODE and AI Toolchain Supply Chain Attacks

The SANDWORM_MODE campaign is a multi-stage npm supply chain worm that targets AI-augmented development workflows by exploiting runtime behaviors of AI coding assistants and CI/CD pipelines, leading to credential theft, supply chain poisoning, and persistence through obfuscated loaders, credential harvesting, and malicious Git hooks.

npm +16 supply-chain-attack git ai-toolchain development-workflow code-injection credential-theft persistence evasion
3r 14t 8i updated
medium advisory

AWS Bedrock Model Prompt or Completion Containing Credentials

A detection rule identifies AWS access key IDs, Amazon Bedrock API keys, PEM private-key blocks, and GitHub/GitLab tokens within Amazon Bedrock model prompts or completions, indicating a critical credential exposure event through misconfiguration, data leakage, or prompt injection that necessitates immediate secret rotation and investigation.

Amazon Bedrock +2 llm aws bedrock credential-access data-leakage prompt-injection
1r 1t
high threat

Analyzing Supply Chain Risks in Python Package Installation

Threat actors, including TeamPCP, are increasingly using malicious Python packages in supply chain attacks to compromise developer devices and infrastructure by exploiting trust in Python's packaging ecosystem, leading to automatic payload execution during installation.

PyPI +2 TeamPCP supply-chain python software-security
2t 4i
high advisory

CVE-2026-61462 - mcp-gitlab Path Traversal Vulnerability Leading to Unauthorized API Access

A path traversal vulnerability, CVE-2026-61462, in the job_id parameter of build/index.js within mcp-gitlab allows attackers to redirect GitLab API requests to arbitrary endpoints by escaping the intended path prefix, leveraging the operator's personal access token for unauthorized access.

mcp-gitlab path-traversal gitlab web-vulnerability cve
1r 2t 1c
high advisory

Multiple Vulnerabilities Discovered in GitLab CE/EE

Multiple vulnerabilities have been discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) across versions 19.0.x, 19.1.x, and 18.11.x, allowing an attacker to compromise data confidentiality, inject remote code via Cross-Site Scripting (XSS) (CVE-2026-11827), and bypass security policies (CVE-2026-13320).

GitLab Community Edition +5 web-application vulnerability gitlab xss data-leak
1t 5c
high advisory

Shai-Hulud Campaign Activity

Tracking brief for the Shai-Hulud campaign; individual sightings are folded in as reported.

jscrambler 8.14.0 +101 campaign shai-hulud
20i updated
high advisory

GitLab: Multiple Vulnerabilities

Multiple vulnerabilities in GitLab allow a remote, authenticated attacker to execute arbitrary code, perform Cross-Site Scripting (XSS), manipulate data, or disclose sensitive information.

GitLab vulnerability web-application rce xss data-exfiltration
3t
medium advisory

Multiple Vulnerabilities in GitLab Lead to DoS and Security Policy Bypass

Multiple vulnerabilities in GitLab CE/EE allow attackers to cause remote denial of service and bypass security policies in versions 18.11.x before 18.11.4, 19.x before 19.0.1, and before 18.10.7; these vulnerabilities are tracked as CVE-2026-1402, CVE-2026-2601, CVE-2026-2710, CVE-2026-4868, CVE-2026-5296, CVE-2026-6713, and CVE-2026-8716.

GitLab Community Edition +1 gitlab vulnerability denial-of-service security-bypass CVE-2026-1402 CVE-2026-2601 CVE-2026-2710 CVE-2026-4868 +3
2r 2t 5c
high advisory

ClearFake, ACR Stealer, and GraphRunner Emerge as Significant Threats

The Red Canary Intelligence Insights report for May 2026 highlights the rise of ClearFake, ACR Stealer, and GraphRunner, with ClearFake using JavaScript injection to deliver malware like ACR Stealer, and GraphRunner being abused for reconnaissance and data exfiltration via the Microsoft Graph API.

Entra ID +6 credential-theft malware oauth
2r 4t 2i
critical advisory

Coder Azure Instance Identity PKCS#7 Signature Bypass Leads to Unauthenticated Agent Token Theft (CVE-2026-46354)

Coder is vulnerable to a PKCS#7 signature bypass in Azure instance identity (CVE-2026-46354), allowing unauthenticated agent token theft via a forged vmId, enabling access to Git SSH private keys, OAuth access tokens, and workspace secrets.

Coder v2 +4 pkcs7 azure instance identity signature bypass unauthenticated access credential theft cve-2026-46354 coder
3r 3t
critical advisory

Arcane Git Repository Authentication Bypass Leads to Credential Exfiltration and GitOps Tampering (CVE-2026-45625)

Arcane's REST API lacks proper admin authorization checks on Git repository management endpoints, allowing any authenticated user to exfiltrate stored Git credentials and tamper with GitOps configurations by redirecting credential requests to an attacker-controlled host.

arcane backend +2 credential-access privilege-escalation supply-chain-compromise denial-of-service information-disclosure cloud authentication-bypass
2r 5t 1i
high advisory

Compromised node-ipc npm Package Steals Credentials

Hackers injected credential-stealing malware into newly published versions of the node-ipc npm package in a supply chain attack, collecting cloud credentials, SSH keys, CI/CD secrets, and other sensitive data, exfiltrating it through DNS TXT queries.

node-ipc +10 supply-chain-attack npm infostealer credential-theft
2r 3t 2i
critical advisory

Multiple Vulnerabilities in GitLab CE/EE Allow for Arbitrary Code Execution, Data Confidentiality Compromise, and SSRF

Multiple vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE) can allow an attacker to perform arbitrary code execution, compromise data confidentiality, perform server-side request forgery (SSRF), and other security breaches.

GitLab Community Edition +1 gitlab vulnerability rce ssrf xss csrf
2r 3c
high advisory

GitLab MCP Server Unauthenticated Access via SSE Transport

The @yoda.digital/gitlab-mcp-server's SSE transport lacks authentication and uses wildcard CORS, enabling unauthenticated attackers to execute arbitrary GitLab API calls using the operator's GitLab PAT, including destructive operations.

@yoda.digital/gitlab-mcp-server gitlab auth-bypass sse cors vulnerability
2r 2t