CVE-2020-10953: GitLab

High severity, CVSS 7.5. EPSS: 1.6% chance of exploitation in the next 30 days.

In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.

Affected products

  • GitLab GitLab: from 11.7.0, up to and including 12.9

Published 2020-03-27. Last modified 2026-06-17.