importantSYS.SOURCE: The Hacker News• 2026-08-21T12:34:25+05:30
GitLab CVE-2026-19478 Code Injection Vulnerability Exploited Post-Disclosure
A critical code injection vulnerability (CVE-2026-19478) in GitLab enables unauthenticated attackers to modify or delete public projects via GraphQL, with active exploitation observed within days of disclosure. Patches are available, but organizations are urged to apply updates promptly due to rapid exploitation timelines.
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.
The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly accessible GitLab projects and rewrite their data under certain conditions without requiring
*** END OF TRANSMISSION ***