CVE-2021-22205
KEV RANSOMWARECRITICAL 10.0EPSS 99.7%
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v3.1
- 10.0 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 99.73% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2021-11-03, used in ransomware campaigns
- Nuclei
- critical · CWE-94
- Published
- 2021-04-23
- Updated
- 2026-08-06
Proof-of-concept exploits (35)
- http://packetstormsecurity.com/files/164768/GitLab-Unauthenticated-Remote-ExifTool-Comman…
- http://packetstormsecurity.com/files/164994/GitLab-13.10.2-Remote-Code-Execution.html
- Al1ex/CVE-2021-22205287★ · 2022-11-16
- DIVD-NL/GitLab-cve-2021-22205-nse1★ · 2021-11-27
- Hikikan/CVE-2021-222050★ · 2023-09-08
- Jeromeyoung/CVE-2021-222100★ · 2021-10-31
- NukingDragons/gitlab-cve-2021-222051★ · 2023-11-01
- Parker-Corbitt/CS4770_CVE0★ · 2023-12-15
- Qclover/Gitlab_RCE_CVE_2021_222050★ · 2021-11-02
- XTeam-Wing/CVE-2021-2220586★ · 2021-10-28
- ZZ-SOCMAP/CVE-2021-222057★ · 2021-11-04
- al4xs/CVE-2021-22205-gitlab0★ · 2022-03-10
- antx-code/CVE-2021-222057★ · 2021-11-04
- asdaweee/GitLabRCECVE-2021-22205-GUI0★ · 2023-07-11
- c0okB/CVE-2021-2220513★ · 2022-07-04
- cc3305/CVE-2021-222050★ · 2024-07-27
- devdanqtuan/CVE-2021-222050★ · 2024-01-20
- findneo/GitLab-preauth-RCE_CVE-2021-222052★ · 2021-10-30
- hh-hunter/cve-2021-222050★ · 2021-11-05
- inspiringz/CVE-2021-22205237★ · 2022-01-16
- j5s/Polaris2★ · 2022-01-03
- keven1z/CVE-2021-2220512★ · 2022-07-25
- liaboveall/SecureGuard-WAF1★ · 2025-10-09
- momika233/cve-2021-22205-GitLab-13.10.2---Remote-Code-Execution-RCE-Unauthenticated-1★ · 2022-04-18
- mr-r3bot/Gitlab-CVE-2021-22205181★ · 2021-11-02
- osungjinwoo/CVE-2021-22205-gitlab0★ · 2022-03-10
- overgrowncarrot1/DejaVu-CVE-2021-222050★ · 2023-08-02
- pizza-power/Golang-CVE-2021-22205-POC3★ · 2021-11-25
- r0eXpeR/CVE-2021-2220569★ · 2021-10-28
- runsel/GitLab-CVE-2021-22205-3★ · 2021-11-05
- shang159/CVE-2021-22205-getshell3★ · 2021-11-01
- w0x68y/Gitlab-CVE-2021-222051★ · 2021-12-22
- whwlsfb/CVE-2021-2220523★ · 2021-10-30
- K3ysTr0K3R/CVE-2021-22205
- ccordeiro/CVE-2021-22205