GitLab Cmd Exec in CI via Claude AG v18.9-<19.1.7,19.2-<19.2.5,19.3-<19.3.1
CVE-2026-18252 Published on August 26, 2026
Inclusion of Functionality from Untrusted Control Sphere in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have executed arbitrary commands in a CI context, due to the Claude agent processing configuration from a user-controlled source.
Vulnerability Analysis
CVE-2026-18252 is exploitable with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
Inclusion of Functionality from Untrusted Control Sphere
The software imports, requires, or includes executable functionality (such as a library) from a source that is outside of the intended control sphere.
Products Associated with CVE-2026-18252
Want to know whenever a new CVE is published for GitLab? stack.watch will email you.
Affected Versions
GitLab:- Version 18.9 and below 19.1.7 is affected.
- Version 19.2 and below 19.2.5 is affected.
- Version 19.3 and below 19.3.1 is affected.