GitLab Attackers Started Exploiting a Critical Flaw Within Minutes of Disclosure

Started by HardyBoy13, Today at 10:32 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: GitLab Attackers Started Exploiting a Critical Flaw Within Minutes of Disclosure   Views(Read 67 times)
Active members in this topic:
HardyBoy13(1)

HardyBoy13

GitLab pushed an emergency out of band patch on 17th August  for a critical vulnerability, tracked as CVE-2026-19478 with a CVSS score of 9.4, that lets a completely unauthenticated attacker remotely modify or delete public projects and user data through a GraphQL directive. Security firm watchTowr says it reproduced the exploit within minutes of the disclosure using nothing but the public advisory and the patch diff itself, and confirmed real world exploitation attempts hitting its honeypot network within roughly two days.

The practical damage an attacker can do here is genuinely severe for anyone running a self managed GitLab instance. According to watchTowr's own researcher, a single HTTP request with no credentials, no user interaction, and no unusual configuration required could delete an entire repository, forge merge records, or ban maintainers outright, which is exactly the kind of supply chain nightmare that could cascade into build failures across every downstream project depending on that code.

The flaw affects GitLab Community Edition and Enterprise Edition versions from 18.2 all the way through 19.2, with fixes only available in 19.2.4, 19.1.6, 19.0.8, and 18.11.11. Anyone still sitting on an older branch inside that 18.2 through 18.10 range is apparently left without an official patch at all, which is a genuinely awkward gap for organizations running slightly older but still officially supported deployments.

What makes this particular case notable beyond the technical details is how openly watchTowr talked about using AI assistance to help reconstruct a working exploit without ever seeing a public proof of concept. That detail alone says something uncomfortable about how quickly the gap between disclosure and real world exploitation is shrinking now that both defenders and attackers have AI tools speeding up the entire reverse engineering process on both sides.

If your organization runs a self managed GitLab instance and has not patched yet, the honest advice from every security outlet covering this is to stop reading and go check your version number right now

Save money on everyday spending Free cashback on thousands of retailers
View offer