ADVERTISEMENT

Critical GitLab flaw lets hackers delete or rewrite repositories – now exploited in wild

GitLab warns the 9.4-rated code injection vulnerability requires no user interaction to exploit – and attackers are already trying.

GitLab

Image by jackpress | Shutterstock

Stefanie Schappert
Stefanie Schappert Senior Journalist
August 18, 2026 Updated: August 19, 2026 3 min read
Key takeaways:
GitLab flaw CVE
The critical GitLab vulnerability, CVE-2026-19478, carries a 9.4 severity score. cve.org

GitLab flaw already being exploited in the wild

As expected, one day later – and we are already seeing in-the-wild exploitation of this vulnerability hit our global Attacker Eye honeypot network,”
watchTowr Principal Security Researcher Jake Knott tells Cybernews.
AI hacker in cyber city
AI tools are shrinking the window between vulnerability disclosure and exploitation. Image by Art Farther | Shutterstock

Critical GitLab flaw needs no user interaction

“It's only Tuesday, and we're already dealing with a critical out-of-band security patch for GitLab instances, and yet again another reminder that supply chain attacks can take many shapes and sizes,"
Knott said.
Researchers reproduce GitLab flaw within minutes.

GitLab Self-Managed users urged to update

  • 18.2 through 18.11.10
  • 19.0 through 19.0.7
  • 19.1 through 19.1.5
  • 19.2 through 19.2.3
ADVERTISEMENT
“These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately,”
the developer collaboration platform said.

Forged merge records pose bigger supply chain risk

attack using Shai-Hulud
Shai-Hulud is among the recent malware campaigns targeting software supply chains. Image by Cybernews
“An attacker can make a malicious change look reviewed and signed off by someone your team trusts. Your pipeline builds it and ships it downstream, and your own audit log swears the whole thing was legitimate,”
Münch says.

GitLab awards researcher $26K bug bounty

GitLab flaw2
GitLab awarded the researcher a $26,010 bug bounty for reporting the critical GitLab flaw. hackerone.com

GitLab patches second GraphQL flaw

Stefanie Schappert
Senior Journalist
ADVERTISEMENT