CVE-2020-13277

MEDIUM LAB

GitLab CE/EE <13.0.5 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2020-13277. PoCs published by EXP-Docs.

AI-analyzed exploit summary This repository provides a functional proof-of-concept for CVE-2020-13277, a GitLab EE logic flaw allowing unauthorized access to private repositories via mirror repository abuse and CI pipeline execution under victim privileges.

Description

An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5

Exploits (2)

nomisec WORKING POC 27 stars
by EXP-Docs · poc
https://github.com/EXP-Docs/CVE-2020-13277

This repository provides a functional proof-of-concept for CVE-2020-13277, a GitLab EE logic flaw allowing unauthorized access to private repositories via mirror repository abuse and CI pipeline execution under victim privileges.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: GitLab EE 10.6.0
Auth required
Prerequisites: GitLab EE 10.6.0 with cracked license · Admin access to configure mirror repositories and runners · DNS hostname resolution for local network bypass
devstral-2 · analyzed Feb 16, 2026 Full analysis →
inthewild WORKING POC
poc
https://github.com/lyy289065406/cve-2020-13277

This repository provides a functional exploit for CVE-2020-13277, a GitLab EE logic vulnerability allowing arbitrary users to bypass access controls and access private repositories. The PoC includes a Docker-based lab environment with scripts to automate setup, license cracking, and exploitation via GitLab's Mirror Repository feature.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: GitLab EE 10.6.0
Auth required
Prerequisites: Docker and Docker Compose installed · GitLab EE 10.6.0 Docker image · Root/admin access to configure GitLab settings
devstral-2 · analyzed Feb 23, 2026 Full analysis →

References (3)

Core 3
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/894569

Scores

CVSS v3 6.3
EPSS 0.0459
EPSS Percentile 89.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Lab Environment

COMMUNITY
Community Lab
docker pull gitlab/gitlab-runner:latest
docker pull gitlab/gitlab-ee:10.6.0-ee.0

Details

CWE
CWE-863
Status published
Products (1)
gitlab/gitlab 10.6.0 - 13.0.5 (2 CPE variants)
Published Jun 19, 2020
Tracked Since Feb 18, 2026