CVE-2022-2884

CRITICAL

GitLab CE/EE <15.1.5-15.3.1 - Authenticated RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2022-2884. PoCs published by Antonio Francesco Sardella, m3ssap0.

AI-analyzed exploit summary This Python script exploits CVE-2022-2884, an authenticated RCE vulnerability in GitLab via the Import from GitHub API endpoint. It sets up a fake GitHub server to intercept and execute arbitrary commands on the target GitLab instance.

Description

A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

Exploits (2)

exploitdb WORKING POC VERIFIED
by Antonio Francesco Sardella · pythonwebappsruby
https://www.exploit-db.com/exploits/51181

This Python script exploits CVE-2022-2884, an authenticated RCE vulnerability in GitLab via the Import from GitHub API endpoint. It sets up a fake GitHub server to intercept and execute arbitrary commands on the target GitLab instance.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GitLab CE/EE (versions 11.3.4 to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3.1)
Auth required
Prerequisites: Valid GitLab private token · Network access to the target GitLab instance · Attacker-controlled server to host the fake GitHub endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 27 stars
by m3ssap0 · poc
https://github.com/m3ssap0/gitlab_rce_cve-2022-2884

This repository contains a Python3 exploit for CVE-2022-2884, an authenticated RCE vulnerability in GitLab CE/EE versions prior to 15.1.5, 15.2.3, and 15.3.1. The exploit leverages the Import from GitHub API endpoint to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: GitLab CE/EE (versions 11.3.4 to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3.1)
Auth required
Prerequisites: Authenticated GitLab user with a private token · Network access to the GitLab instance · Attacker-controlled server to receive the reverse shell or command output
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.9
EPSS 0.7740
EPSS Percentile 99.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-78
Status published
Products (1)
gitlab/gitlab 11.3.4 - 15.1.5 (2 CPE variants)
Published Oct 17, 2022
Tracked Since Feb 18, 2026