{"slug": "critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos", "title": "Critical GitLab flaw allows attackers to delete and modify public repos", "summary": "GitLab has patched a critical vulnerability, CVE-2026-19478, that could let unauthenticated attackers modify or delete public repositories via a single HTTP request, along with a high-risk CSRF flaw (CVE-2026-19650). Security firm watchTowr reproduced the exploit within minutes of disclosure, warning that AI-enabled attackers are likely to follow. GitLab released versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for both Community and Enterprise Editions, and advises users to make repositories private and block unauthenticated access to the /api/graphql endpoint.", "body_md": "GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request. The patched releases also address a second high-risk cross-site request forgery (CSRF) flaw.\n\nThe critical vulnerability, tracked as [CVE-2026-19478](https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/), is described as a code injection issue through the GraphQL directive and was reported privately to GitLab through its bug bounty program on HackerOne.\n\nHowever, even if the flaw’s details are not yet public, researchers from security firm watchTowr warn that it’s extremely easy to reverse-engineer the patches and build an exploit.\n\n“WatchTowr was able to reproduce the vulnerability within minutes of its disclosure, armed only with the advisory details and patch,” Jake Knott, principal security researcher at watchTowr, tells CSO. “AI-enabled attackers are unlikely to be far behind.”\n\nGitLab is a popular source code management system and DevOps platform, complete with CI/CD pipelines and security scanning. The fact that users can self-host it on their own servers makes it an attractive alternative to GitHub, especially for organizations, which is why the software comes in two variants, a free Community Edition (CE) and a paid Enterprise Edition (EE).\n\nThe code injection vulnerability is very dangerous especially for GitLab instances exposed directly to the internet because it can lead to software supply chain attacks. The flaw allows attackers to rewrite the state of GitLab repositories, forge merge records, ban maintainers, and even delete entire projects. The exploit doesn’t require credentials, user interaction, or special configurations.\n\nGitLab released versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 for both CE and EE editions to patch CVE-2026-19478 and CVE-2026-19650, a CSRF issue in the GraphQL multiplex query handler.\n\nUsers who can immediately deploy the patches are advised to make their repositories private and to block unauthenticated access to the `/api/graphql`\n\nendpoint.", "url": "https://wpnews.pro/news/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos", "canonical_source": "https://www.csoonline.com/article/4211140/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.html", "published_at": "2026-08-18 19:33:31+00:00", "updated_at": "2026-08-18 19:40:56.791782+00:00", "lang": "en", "topics": ["ai-safety"], "entities": ["GitLab", "watchTowr", "Jake Knott", "HackerOne", "CVE-2026-19478", "CVE-2026-19650"], "alternates": {"html": "https://wpnews.pro/news/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos", "markdown": "https://wpnews.pro/news/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.md", "text": "https://wpnews.pro/news/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.txt", "jsonld": "https://wpnews.pro/news/critical-gitlab-flaw-allows-attackers-to-delete-and-modify-public-repos.jsonld"}}