started · updated
GitLab critical vulnerability actively exploited in the wild
A critical code injection vulnerability in GitLab, tracked as CVE-2026-19478, is being actively exploited in the wild. The flaw, which carries a CVSS score of 9.4, allows unauthenticated remote attackers to exploit a GraphQL directive to modify or delete public projects, rewrite data, forge merge records, and ban project maintainers without requiring credentials or user interaction.
Security firm watchTowr reported that exploitation was observed within days of the vulnerability's disclosure. The firm noted that attackers may be using AI to accelerate the time between disclosure and exploitation.
The vulnerability affects several versions of GitLab Community Edition (CE) and Enterprise Edition (EE), specifically within the 18.x and 19.x release branches. Affected versions include 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.
GitLab has released patches in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11. While GitLab.com and GitLab Dedicated are already running patched versions, organizations operating self-managed, internet-facing instances are urged to upgrade immediately or restrict GraphQL API access as a mitigation.