Known Vulnerabilities for Runner by Gitlab
Listed below are 3 of the newest known vulnerabilities associated with "Runner" by "Gitlab".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-67426 json | Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification ... | Not Provided | 2026-07-29 | 2026-07-29 |
| CVE-2026-61437 json | PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._r... | Not Provided | 2026-07-10 | 2026-07-14 |
| CVE-2026-58053 json | Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job... | Not Provided | 2026-06-28 | 2026-06-30 |
| CVE-2026-57531 json | Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows un... | Not Provided | 2026-07-24 | 2026-07-25 |
| CVE-2026-57530 json | Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/... | Not Provided | 2026-07-24 | 2026-07-25 |
| CVE-2026-56777 json | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Cod... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-56776 json | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/new en... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-55576 json | MaaAssistantArknights is a one-click tool for daily Arknights tasks. In the current dev-v2 workflow, .github/workflows/releas... | Not Provided | 2026-07-15 | 2026-07-18 |
| CVE-2026-54695 json | Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Prior to 1.4.0,... | Not Provided | 2026-07-09 | 2026-07-10 |
| CVE-2026-54344 json | ToolJet is an open-source low-code platform for building internal tools. Prior to 3.20.180, ToolJet's render preview deployme... | Not Provided | 2026-07-08 | 2026-07-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gitlab | Runner | 9.5.1 | |||
| Application | Gitlab | Runner | 9.5.0 | |||
| Application | Gitlab | Runner | 9.5.0 | |||
| Application | Gitlab | Runner | 9.4.3 | |||
| Application | Gitlab | Runner | 9.4.2 | |||
| Application | Gitlab | Runner | 9.4.1 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.4.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.3.0 | |||
| Application | Gitlab | Runner | 9.2.2 | |||
| Application | Gitlab | Runner | 9.2.1 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.2.0 | |||
| Application | Gitlab | Runner | 9.1.3 | |||
| Application | Gitlab | Runner | 9.1.2 |