CVE-2023-1708: GitLab

Critical severity, CVSS 9.8. EPSS: 1.1% chance of exploitation in the next 30 days.

An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

Affected products

  • GitLab GitLab: from 1.0.0, before 15.8.5 (fixed in 15.8.5); from 15.9.0, before 15.9.4 (fixed in 15.9.4); version 15.10.0 only

Published 2023-04-05. Last modified 2026-06-17.