CVE-2023-2825

Confirmed PUBLISHED

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal...

Vendor: GitLab Product: GitLab

Not yet in CISA KEV

Exploited in the wild Active exploitation observed PoC available

Recommended Action

Prioritize immediate patching and validate internet-facing exposure. Monitor for matching exploitation attempts in your environment.

Confidence
Confirmed
Exploitation Status
Active exploitation observed
Observed in Sensors
Yes
Attempts (30d)
4
Unique Attacker IPs
2
CISA KEV
Not yet in CISA KEV
CVSS / EPSS
10.0 Critical EPSS 71.6%

At a Glance

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVE Published
May 26, 2023
Exploited Since
Jul 29, 2026
CVSS
10.0 Critical
EPSS
71.6%
Remote Low complexity No user interaction Unauthenticated

Sensor telemetry available

Affected Versions

Vendor Product Version Status
GitLab
GitLab

16.0.0

Affected

CVE References