cscli appsec-rules install crowdsecurity/vpatch-CVE-2026-857061name: crowdsecurity/vpatch-CVE-2026-857062description: 'Detects GitLab unauthenticated arbitrary file read (CVE-2026-85706) via client-supplied file.path/file.size parameters'3rules:4 # Workhorse matches upload routes on the still-encoded path while Puma decodes first, so5 # the route guard can be dodged many ways (%66iles, %63ommits, a bare trailing slash).6 # Rails then reads the literal 'file.path' key, which only Workhorse should ever inject,7 # so anchoring on that key rather than the encoding trick survives unpublished variants.8 - or:9 - and:10 - zones:11 - URI12 transform:13 - lowercase14 - urldecode15 match:16 type: contains17 value: '/api/v4/'18 - zones:19 - ARGS_NAMES20 transform:21 - lowercase22 - urldecode23 match:24 type: regex25 value: '^file\.(path|size)$'26 - and:27 - zones:28 - URI29 transform:30 - lowercase31 - urldecode32 match:33 type: contains34 value: '/api/v4/'35 - zones:36 - BODY_ARGS_NAMES37 transform:38 - lowercase39 - urldecode40 match:41 type: regex42 value: '^file\.(path|size)$'4344labels:45 type: exploit46 service: http47 confidence: 348 spoofable: 049 behavior: 'http:exploit'50 label: 'GitLab - LFI'51 classification:52 - cve.CVE-2026-8570653 - attack.T119054 - cwe.CWE-22