Description
An issue has been discovered in GitLab affecting all versions before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. The main branch of a repository with a specially crafted name allows an attacker to create repositories with malicious code, victims who clone or download these repositories will execute arbitrary code on their systems.
References (3)
Core 3
Core References
Third Party Advisory
https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0756.json
Permissions Required
https://hackerone.com/reports/1864278
Scores
CVSS v3
4.8
EPSS
0.0056
EPSS Percentile
68.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
no
Technical Impact
total
Details
Status
published
Products (1)
gitlab/gitlab
< 15.9.6
Published
May 03, 2023
Tracked Since
Feb 18, 2026