Critical GitLab flaw allows attackers to delete and modify public repos

Chronological Source Flow
Back

AI Fusion Summary

GitLab has patched a critical zero-click vulnerability, CVE-2026-19478, which allowed unauthenticated attackers to modify or delete public repositories via a single HTTP request. This code injection flaw, discovered through the HackerOne bug bounty program, involves the GraphQL directive. Additionally, a high-risk CSRF flaw was addressed. While GitLab has not released full technical details, watchTowr researchers warn that the patches are easily reverse-engineered, creating detection and mitigation challenges for organizations using self-managed GitLab versions.
Community Comments
Loading updates...
0