Bg ShapeBg Shape
THREAT INTELLIGENCE

GitLab CE/EE Vulnerability Actively Exploited

Affected Environment
GitLab CE/EE versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4.

Threat Overview
A critical code injection flaw in a GraphQL directive is being actively exploited, letting attackers modify or delete public projects and data.

Exposure Timeline
Disclosed and remediated 25 to 26 August 2026, with active exploitation already confirmed at the time of publication.

Attack Surface
GitLab's GraphQL API, reachable by unauthenticated remote attackers against any internet-facing instance running an affected version.

Technical Root Cause
Insufficient input validation within a GraphQL directive results in a code injection condition under certain configuration conditions.

Exploitation Pathway
An unauthenticated attacker sends a crafted GraphQL request to remotely modify or delete public projects and associated user data.

Operational Impact
Successful exploitation lets an unauthenticated attacker delete or tamper with public projects and user data without any credentials.

Strategic Impact
Rated Critical for all government and business entity sizes given GitLab's widespread use for source control and CI/CD pipelines.

Required Mitigation
Apply GitLab's patched releases immediately; upgrade software, operating systems and firmware on network assets without delay.

Incident Response Guidance
Review GraphQL API logs for unexpected project modification or deletion requests, and confirm patch levels across all instances.

References
NCSC Ireland, NVD, CVE.org, GitLab patch release notes, GitHub exploit intelligence repository.

Download the Full Report

Explore More of the Latest Threat Intelligence

Trusted by clients worldwide

Logo
Logo
Logo
Logo
Logo
Logo

Your 24/7 Security Partner

Led by human expertise and powered by the VisionX platform, we provide you with a 24/7 unbeatable Managed Detection & Response capability giving you transparent and consolidated security solutions.

Awards Image
Awards Image
Awards Image
Awards Image
Awards Image
Awards Image