Critical GitLab Bugs Let Attackers Execute Code Through Malicious CI/CD Regex
GitLab patched two CVSS 9.9 flaws letting authenticated users execute code via malicious CI/CD regular expressions.
GitLab released emergency patches for two critical flaws, CVE-2026-89078 and CVE-2026-93577, both scored CVSS 9.9. An authenticated user can place a crafted regular expression in a CI/CD configuration to trigger a double-free or an integer overflow and potentially execute code on the GitLab server. Affected releases are GitLab CE and EE 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The update also fixes high-severity XSS CVE-2026-84739 and authorization flaw CVE-2026-92470 in GitLab Duo AI job troubleshooting.
74