GitLab has a critical security hole: CVE-2026-19478 (CVSS 9.4) lets unauthenticated remote attackers modify or delete public projects and user data. The flaw is already being actively exploited.
Why the flaw is so dangerous
It is a code injection through a GraphQL directive – with no login, no user interaction and no special configuration required. Attackers can use it to rewrite repositories, forge merge records, ban maintainers and delete entire projects.
Patch now
The bug is fixed in versions 19.2.4, 19.1.6, 19.0.8 and 18.11.11. All self-managed GitLab installations should be updated immediately; GitLab.com and GitLab Dedicated already run the patched version. Attackers began exploiting it roughly two days after disclosure – the flaw was reproducible within minutes. Anyone who has not patched yet should search their web logs for requests containing @gl_introduced.
Sources: Help Net Security, SecurityWeek.



















