← Vulnerability feed

Vulnerability record · CVE-2023-2825 · published 26 May 2023

CVE-2023-2825: GitLab CE/EE path traversal allows unauthenticated arbitrary file read

Gitlab · Gitlab

GitLab CE/EE version 16.0.0 contains a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files on the server. It is exploitable only when an attachment exists in a public project nested within at least five groups, which narrows the affected population but leaves exposed instances fully readable. The CVSS 3.1 base score is 7.5 (HIGH) with confidentiality impact only.

7.5 CVSS 3.1 High EPSS 72% · top 0.6% CWE-22 · Path traversal
7.5CVSS 3.1 base score
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable arbitrary file read with a 7.5 CVSS score and very high EPSS, though exploitation requires a specific public-project nesting precondition.

What it is

GitLab CE/EE version 16.0.0 contains a path traversal flaw (CWE-22) that lets an unauthenticated attacker read arbitrary files on the server. It is exploitable only when an attachment exists in a public project nested within at least five groups, which narrows the affected population but leaves exposed instances fully readable. The CVSS 3.1 base score is 7.5 (HIGH) with confidentiality impact only.

Impact

An attacker gains read access to arbitrary files on the GitLab server, which can expose repository data, configuration and secrets stored on the host. There is no integrity or availability impact per the CVSS vector.

Attack surface

Reachable over the network with no authentication and no user interaction (AV:N/AC:L/PR:N/UI:N). The precondition is a public project nested within at least five groups that contains an attachment.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.716 probability (99.4th percentile), indicating strong likelihood of attempted exploitation. Reference tags are advisory and HackerOne report links only, with no public exploit tag supplied.

What to do

  • Upgrade GitLab CE/EE from 16.0.0 to a fixed release as the primary action.
  • If immediate upgrade is not possible, restrict or remove public projects nested five or more groups deep and audit attachments in those projects.
  • Reduce nesting depth of public projects and review group visibility settings to eliminate the required precondition.
  • Monitor GitLab advisories and the vendor CVE record for the fixed version and backport guidance.
  • Treat any host running 16.0.0 as potentially compromised and review file access logs.

Detection

  • Search GitLab access logs for requests to attachment endpoints containing traversal sequences such as ../ or encoded variants.
  • Alert on unauthenticated requests to project attachment paths that return 200 with unexpected content types or sizes.
  • Inventory GitLab instances and flag any running version 16.0.0.
  • Correlate outbound or file-read anomalies on GitLab hosts with attachment endpoint access from unauthenticated sessions.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2825 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2023-2825), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.