Unauthenticated GraphQL injection lets strangers wipe GitLab projects

GitLab shipped emergency patches for a critical GraphQL code injection flaw that lets unauthenticated attackers modify or delete public projects.

CSBadmin
1 Min Read

Self-managed GitLab deployments are getting emergency patches for a critical hole that leaves public projects and user data exposed to unauthenticated attackers.

The bug, CVE-2026-19478, carries a CVSS score of 9.4 and stems from code injection through a GraphQL directive. It can be exploited remotely with zero credentials and no user interaction, according to the company’s advisory.

A second issue, CVE-2026-19650 (CVSS 7.1), is a cross-site request forgery in the GraphQL multiplex query handler that allows mutations via GET requests, though it needs user interaction to fire.

Both Community Edition and Enterprise Edition are exposed. Vulnerable versions span 18.2 up to 18.11.10, 19.0 up to 19.0.7, 19.1 up to 19.1.5, and 19.2 up to 19.2.3. Fixes land in 18.11.11, 19.0.8, 19.1.6, and 19.2.4.

GitLab.com and GitLab Dedicated already run patched builds and need no action, but admins of self-managed installs are urged to upgrade immediately. Both bugs were reported through the HackerOne bug bounty program.

Organizations running self-managed GitLab should prioritize the update and review audit logs for signs of project deletion or data modification before patching. GraphQL-facing services should be treated as externally reachable and tested accordingly.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.