GitLab shipped emergency patches for a critical GraphQL code injection flaw that lets unauthenticated attackers modify or delete public projects.