← Back

Wire · technology

Critical and High-Severity GraphQL CVEs in GitLab: Code Injection and CSRF via One Directive

Published

19 August 2026

Topic

technology

◆ Sectors

Enterprise Software

◆ Source

Read at ox.security →

◆ Verified

Fusion42 · 21 August 2026 · Fusion42 review

Two critical GraphQL vulnerabilities in GitLab's self-managed instances enable unauthenticated code injection and CSRF attacks affecting public projects and user data, fixed in recent GitLab patch releases.

This Wire brief sits within Fusion42's coverage of Enterprise Software, and 4 sources have reported it between 17 Aug 2026 and 21 Aug 2026.

◆ ◆ The Wire takeaway

You must patch your self-managed GitLab now to avoid unauthenticated code execution risks via GraphQL. Ignoring this leaves public project data exposed to deletion and modification without any extra permission.

◆ Coverage

4 sources · first reported 17 Aug 2026 · latest 21 Aug 2026

◆ Related on Wire

◆ Topics

Enterprise Softwaregraphqlsecuritycvegithubpatchself-managed