← Vulnerability feed

Vulnerability record · CVE-2022-2884 · published 17 October 2022

CVE-2022-2884: GitLab GitHub import API command injection enables remote code execution

Gitlab · Gitlab

GitLab CE/EE contains an OS command injection flaw (CWE-78) in the Import from GitHub API endpoint. An authenticated user can leverage it to execute arbitrary commands on the server, and the affected range spans versions from 11.3.4 up to before 15.1.5, plus 15.2 through 15.2.3 and 15.3 through 15.3.1. With a CVSS 3.1 score of 9.9 and a scope-changing vector, this is a severe issue for any exposed GitLab instance.

9.9 CVSS 3.1 Critical EPSS 76% · top 0.5% CWE-78 · OS command injection
9.9CVSS 3.1 base score
76%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 9.9 with scope change, authenticated remote code execution, and very high EPSS make this an urgent patch target despite no KEV listing.

What it is

GitLab CE/EE contains an OS command injection flaw (CWE-78) in the Import from GitHub API endpoint. An authenticated user can leverage it to execute arbitrary commands on the server, and the affected range spans versions from 11.3.4 up to before 15.1.5, plus 15.2 through 15.2.3 and 15.3 through 15.3.1. With a CVSS 3.1 score of 9.9 and a scope-changing vector, this is a severe issue for any exposed GitLab instance.

Impact

An attacker with a valid account gains remote code execution on the GitLab host, which can lead to full compromise of the application and its data. Because the CVSS scope is changed, impact can extend beyond the vulnerable component to the underlying system.

Attack surface

The flaw is reached over the network through the Import from GitHub API endpoint. It requires authentication (PR:L) but no user interaction (UI:N), so any low-privileged account is sufficient to attempt exploitation.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high at roughly 0.757 (99.5th percentile), and public references include a Packet Storm write-up and a HackerOne report, indicating exploit knowledge is publicly available. No ransomware group usage is documented in the record.

What to do

  • Upgrade GitLab CE/EE to 15.1.5, 15.2.4, 15.3.2 or later, which are the fixed releases for the affected ranges.
  • If immediate upgrade is not possible, restrict or disable the Import from GitHub feature and limit API access to trusted users.
  • Audit and reduce the number of authenticated accounts, and enforce least privilege so low-privileged users cannot reach import functionality.
  • Monitor GitLab server logs and process activity for unexpected command execution originating from the import endpoint.
  • Apply network controls so GitLab is not directly reachable from untrusted networks where possible.

Detection

  • Review GitLab production logs for Import from GitHub API requests, especially from accounts that do not normally use imports.
  • Hunt for anomalous child processes spawned by the GitLab web/worker processes, such as shells or unexpected binaries.
  • Alert on outbound network connections from the GitLab host to unfamiliar destinations following import activity.
  • Correlate authentication events with import endpoint access to identify low-privileged accounts triggering the feature.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-2884 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-2884), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.