Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
gitlab-cve-2026-85706-ioc — CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules. | Kitploit
Tools/GitHubGitHub/jithinkrishnanrs/gitlab-cve-2026-85706-ioc
Defensive ToolsIndicator of Compromise (IOC) ManagementVulnerability ScannersThreat Feeds & AggregatorsVulnerability AnalysisInformation GatheringWeb SecurityNetwork Security

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Threat Intelligence
Incident Response
Log Analysis
GitHubjithinkrishnanrs/gitlab-cve-2026-85706-ioc

gitlab-cve-2026-85706-ioc

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit. Detect and hunt for exploitation of the critical unauthenticated GitLab CE/EE path traversal vulnerability with IOC scanning, Sigma, Suricata/Snort, and SIEM detection rules.

View Repository
15119 days agoNot yet reviewed
Share

CVE-2026-85706 — GitLab Path Traversal IOC Scanner & Detection Toolkit

GitLab CE/EE Repository Commits API Unauthenticated Path Traversal (CVSS 3.1: 10.0, Critical) Status: Actively exploited in the wild · Listed in CISA KEV (2026-09-11, due 2026-09-14) · Patched by GitLab 2026-09-10

CI License: MIT CVSS CISA KEV GitHub issues GitHub stars

A free, open-source incident response and threat hunting toolkit for CVE-2026-85706 — a critical, unauthenticated path traversal vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the repository commits API. This repository gives security teams, SOC analysts, detection engineers, and GitLab administrators a ready-to-run IOC (Indicators of Compromise) scanner, Sigma / Suricata / Snort detection rules, Splunk / Elastic / OpenSearch hunting queries, and a step-by-step remediation guide — everything you need to detect exploitation attempts, confirm patch status, and respond to this GitLab zero-day / n-day vulnerability quickly.

🔎 Looking for the fastest path to "am I affected?" Jump to Quick Start.

🚨 Looking for what to patch to? Jump to Fixed Versions & Patch.


Table of Contents

  • Vulnerability Summary
  • Why This Matters
  • Fixed Versions & Patch
  • Related Vulnerabilities Fixed in the Same Release
  • Repository Contents
  • Quick Start
    • 1. Scan your GitLab logs for IOCs
    • 2. Check if your GitLab version is patched
    • 3. Deploy detection rules to your SIEM / IDS
  • How the Scanner Works
  • Sample Output
  • Indicators of Compromise (IOC) Summary
  • Detection Content
  • Remediation
  • Frequently Asked Questions
  • Limitations & Disclaimer
  • Contributing
  • Sources & Further Reading
  • License

Vulnerability Summary

CVE IDCVE-2026-85706
Vendor / ProductGitLab Community Edition (CE) & Enterprise Edition (EE), self-managed
Vulnerability classPath Traversal (CWE-35), part of the broader Improper Limitation of a Pathname family (CWE-22)
Affected componentRepository Commits API (/api/v4/projects/:id/repository/commits...)
Root causeImproper path confinement combined with missing authentication enforcement in the affected API endpoint
Affected versionsGitLab CE/EE 18.7 through 19.1.7, 19.2 through 19.2.5, 19.3 through 19.3.1 (last vulnerable patch on each branch; anything on an older, unsupported branch is presumed vulnerable too)
Authentication requiredNone — unauthenticated, pre-auth exploitation
Attack vectorNetwork, single HTTP POST request to the commits API
CVSS 3.1 score10.0 (Critical) — vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N (Scope Changed, no availability impact — this is a read-only file-disclosure primitive)
ImpactArbitrary file read on the GitLab server — configuration files, secrets, tokens, source code, potentially SSH keys and database credentials
Reported byExternal security researcher (HackerOne handle "s3ntago"), via GitLab's HackerOne bug bounty program
Disclosed / PatchedSeptember 10, 2026 — part of a critical GitLab security release fixing 17–18 vulnerabilities in total, reported variably by different outlets (see Related Vulnerabilities)
Estimated exposureIndependent reporting estimates 20,000+ internet-facing self-managed GitLab instances globally were running an affected version at disclosure
CISA KEVAdded September 11, 2026; federal civilian remediation due September 14, 2026 (3 calendar days); this places CVE-2026-85706 in CISA's highest-risk tier under Binding Operational Directive (BOD) 26-04 ("Prioritizing Security Updates Based on Risk," effective June 10, 2026, superseding BOD 22-01) — the tier reserved for vulnerabilities that are KEV-listed, publicly exposed, automatable, and capable of yielding full system control, which also mandates forensic triage to determine whether a system was already compromised before patching, not just theoretically exposed
Exploitation statusConfirmed active scanning / probing observed in the wild. Reporting on timing varies: watchTowr's initial "Rapid Reaction" write-up is most commonly cited as observing exploitation attempts roughly 24 hours after disclosure, while at least one outlet (citing watchTowr) reports probes beginning within six hours. Either way, the exploitation window from patch to attack was extremely short.
Public PoCNot confirmed publicly available at time of writing
GitLab.com / DedicatedGitLab.com (SaaS) was already patched at disclosure; GitLab Dedicated customers did not need to take action. Only self-managed CE/EE instances require action
Official CISA hunting guidanceCISA and multiple outlets (e.g. The Hacker News) specifically recommend reviewing logs for HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing a file.Path parameter — this is exactly the detection logic implemented by this repository's scanner and detection rules

An unauthenticated attacker can send a single crafted HTTP POST request to GitLab's repository commits API endpoint (/api/v4/projects/{id}/repository/commits/), supplying a file.Path (also seen documented as file.path / file_path) parameter containing directory-traversal sequences (../, URL-encoded variants, etc.), and have the server return the contents of arbitrary files outside the intended repository directory — including GitLab's own secrets file, database configuration, SSH private keys, and other sensitive server-side data. Because no credentials are required and the request is trivial to construct, GitLab and third-party researchers rate this as maximum severity (CVSS 10.0) and CISA has confirmed active exploitation in the wild.

Why This Matters

Download Tool