GitLab 已修复一处影响 GitLab CE/EE 的漏洞,该漏洞存在于所有低于 19.2.7 的 18.3 版本、低于 19.3.3 的 19.3 版本以及低于 19.4.1 的 19.4 版本中。在某些特定条件下,由于授权检查机制存在缺陷,持有 MCP 作用域令牌(MCP-scoped token)的经过身份验证的用户可能会执行超出该令牌预期作用范围的操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-89078 | 9.9 CRITICAL | Double Free in GitLab |
| CVE-2026-93577 | 9.9 CRITICAL | Integer Overflow or Wraparound in GitLab |
| CVE-2026-92470 | 7.7 HIGH | Missing Authorization in GitLab |
| CVE-2026-92530 | 4.3 MEDIUM | Use of Less Trusted Source in GitLab |
| CVE-2026-92529 | 4.3 MEDIUM | Incorrect Authorization in GitLab |
| CVE-2026-92628 | 3.1 LOW | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition' |
No comments yet