CVE-2021-22205
CISA KEVPublished November 3, 2021 · Updated April 3, 2026
high
Official Description+
GitHub Community and Enterprise Editions that utilize the ability to upload images through GitLab Workhorse are vulnerable to remote code execution. Workhorse passes image file extensions through ExifTool, which improperly validates the image files.
Affected Products
| Vendor | Product |
|---|---|
| GitLab | Community and Enterprise Editions |
Patch Status
Patch by 2021-11-17
Recommended Actions
- Check if your systems use any of the affected products listed above.
- Apply vendor patches immediately if available.
- This vulnerability is in CISA's Known Exploited Vulnerabilities catalog — prioritize remediation.
- Monitor vendor advisories for updates and additional mitigations.
- Review logs for indicators of compromise related to CVE-2021-22205.