CVE-2020-10953: GitLab
High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
Affected products
- GitLab GitLab: from 11.7.0, up to and including 12.9
Published 2020-03-27. Last modified 2026-06-17.