EIP-2026-114700
PRE-CVEGitlab 13.9.3 - Remote Code Execution (Authenticated)
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-114700. PoCs published by enox.
AI-analyzed exploit summary This exploit leverages an authenticated RCE vulnerability in GitLab versions prior to 13.9.4 by manipulating the wiki syntax highlighter options to execute arbitrary commands. It authenticates, creates a project, pushes malicious wiki files, and triggers the payload via a crafted request.
Description
Gitlab 13.9.3 - Remote Code Execution (Authenticated)
Exploits (1)
This exploit leverages an authenticated RCE vulnerability in GitLab versions prior to 13.9.4 by manipulating the wiki syntax highlighter options to execute arbitrary commands. It authenticates, creates a project, pushes malicious wiki files, and triggers the payload via a crafted request.