GHSA-x4jh-5c6x-h92v
GitHub Security Advisory
⚠ Unreviewed
HIGH
Has CVE
Advisory Details
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 16, 2025 6:25 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.