GitLab Repository Commits API Path Traversal Arbitrary File Read Exploit

CVE-2026-85706 is an improper path confinement and missing authentication vulnerability in the GitLab repository commits API. A remote unauthenticated attacker can forge Workhorse body-upload metadata and make GitLab read an arbitrary local file before authentication is enforced. This module sends a crafted form to the repository commits API and extracts file content reflected by a parser error. The request does not require a GitLab account, but PROJECT ID must identify an existing project that is available to unauthenticated users. The requested file is interpreted as URL-encoded form data and its content is returned only when parsing encounters malformed percent encoding. Ampersand and semicolon characters separate parameters, while the first equals sign separates a parameter name from its value. The error response includes only the name or value being decoded when the error occurs. The module cannot select a byte offset or resume parsing, so it may disclose only part of a file or no content at all. This exploit does not install an agent.
Exploit Platform
Product Name