Earlier this week, GitLab released details of a code injection vulnerability in its GitLab Community and Enterprise Editions, alongside a critical patch release fixing the issue.
CVE-2026-19478 is a code injection vulnerability in all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4; under “certain conditions”, an attacker would be able to modify or even delete projects remotely via a GraphQL directive.
The vulnerability has a CVSS score of 9.4 and was discovered by a security researcher calling themselves hiimguardian, and reported via GitLab’s HackerOne bug bounty program.
“We strongly recommend that all installations running a version affected by the issues described … are upgraded to the latest version as soon as possible,” GitLab said on August 17.
Researchers at cyber security firm WatchTowr were able to replicate the vulnerability and described it as a supply chain attack waiting to happen.
“The newly disclosed code injection vulnerability allows an unauthenticated attacker to delete publicly accessible GitLab projects and rewrite their state, deleting repositories entirely, forging merge records, or banning maintainers in a single HTTP request with no credentials, user interaction, or obscure configuration required,” Jake Knott, the company’s Principal Security Researcher, said at the time.
“Organisations running internet-facing self-hosted GitLab instances should prioritise upgrading to a patched release. Where that is not possible, restricting unauthenticated access to ‘/api/graphql’, or removing public repository access entirely can be used as a mitigation.”
However, as of August 21, it appears that organisations that have not yet patched may be inviting trouble, as WatchTowr is already observing active exploitation.
“As expected, one day later - and we are already seeing in-the-wild exploitation of this vulnerability hit our global Attacker Eye honeypot network,” Knott reported.
“This is the new reality of vulnerability reproduction and exploitation, where AI-enabled attackers are able to compress the time from disclosure to exploitation and ‘waiting until the next patch cycle’ is often too late.
“Organisations that haven't patched yet should hunt through web logs for requests containing ‘@gl_introduced’, and look for signs of probes or attempted exploitation.”
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.