AllCyberNews

CVE-2026-19478

Improper Control of Generation of Code ('Code Injection') in GitLab

CVSS 9.4 critical · GitLab GitLab · published 2026-08-17

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Coverage 2 sources

  1. 2026-08-18 Help Net Security critical Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

    GitLab patches critical code injection flaw allowing attackers to modify or delete public projects.

  2. 2026-08-19 GovInfoSecurity critical GitLab Code Injection Flaw Exploited in the Wild

    CVE-2026-19478, a GitLab code injection flaw, is being exploited in the wild, allowing unauthenticated attackers to alter public projects.

Also covered