Skip to main content

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Severity

CVSS 3.1 · CNA9.4 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
SSVC · CISA-ADP
Exploitationnone
Automatableyes
Technical impactpartial

Affected Products

VendorProductAffected versions
GitLabGitLab
18.2 to <18.11.11
19.0 to <19.0.8
19.1 to <19.1.6
19.2 to <19.2.4

References

3 Links

Record Details

Published
2026-08-17
Last updated
2026-08-17
Assigner (CNA)
GitLab
Credited to
Thanks [hiimguardian](https://hackerone.com/hiimguardian) for reporting this vulnerability through our HackerOne bug bounty program

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.