CVE-2026-35452: AVideo: Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php
(updated )
The plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces User::isAdmin(). The log contains internal filesystem paths, remote server URLs, and SSH connection metadata.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-35452 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →