{"id":9178,"date":"2026-08-18T19:33:31","date_gmt":"2026-08-18T19:33:31","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9178"},"modified":"2026-08-18T19:33:31","modified_gmt":"2026-08-18T19:33:31","slug":"critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9178","title":{"rendered":"Critical GitLab flaw allows attackers to delete and modify public repos"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw.<\/p>\n<p class=\"wp-block-paragraph\">The critical vulnerability, tracked as <a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-2-4-released\/\">CVE-2026-19478<\/a>, is described as a code injection issue through the GraphQL directive and was reported privately to GitLab through its bug bounty program on HackerOne.<\/p>\n<p class=\"wp-block-paragraph\">However, even if the flaw\u2019s details are not yet public, researchers from security firm watchTowr warn that it\u2019s extremely easy to reverse-engineer the patches and build an exploit.<\/p>\n<p class=\"wp-block-paragraph\">\u201cWatchTowr was able to reproduce the vulnerability within minutes of its disclosure, armed only with the advisory details and patch,\u201d Jake Knott, principal security researcher at watchTowr, tells CSO. \u201cAI-enabled attackers are unlikely to be far behind.\u201d<\/p>\n<p class=\"wp-block-paragraph\">GitLab is a popular source code management system and DevOps platform, complete with CI\/CD pipelines and security scanning. The fact that users can self-host it on their own servers makes it an attractive alternative to GitHub, especially for organizations, which is why the software comes in two variants, a free Community Edition (CE) and a paid Enterprise Edition (EE).<\/p>\n<p class=\"wp-block-paragraph\">The code injection vulnerability is very dangerous especially for GitLab instances exposed directly to the internet because it can lead to software supply chain attacks. The flaw allows attackers to rewrite the state of GitLab repositories, forge merge records, ban maintainers, and even delete entire projects. The exploit doesn\u2019t require credentials, user interaction, or special configurations.<\/p>\n<p class=\"wp-block-paragraph\">GitLab released versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for both CE and EE editions to patch CVE-2026-19478 and CVE-2026-19650, a CSRF issue in the GraphQL multiplex query handler.<\/p>\n<p class=\"wp-block-paragraph\">Users who can immediately deploy the patches are advised to make their repositories private and to block unauthenticated access to the \/api\/graphql endpoint.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw. The critical vulnerability, tracked as CVE-2026-19478, is described as a code injection issue through [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9179,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9178","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9178"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9178"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9178\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9179"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9178"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9178"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9178"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}