Impact
GitLab contains a code injection flaw that allows an attacker to construct malicious GraphQL directives. When processed, these directives enable modification or removal of public projects and user information. The vulnerability is classified as CWE‑94 and can be exploited remotely without authentication, directly compromising data integrity. Based on the description, it is inferred that an attacker could target any public project exposed through the GraphQL endpoint and inject code to alter or delete resources.
Affected Systems
The issue impacts all public installations of GitLab from version 18.2 up to but not including 18.11.11, from 19.0 up to but not including 19.0.8, from 19.1 up to but not including 19.1.6, and from 19.2 up to but not including 19.2.4. Versions 18.11.11, 19.0.8, 19.1.6, and 19.2.4 or later include the vendor fix.
Risk and Exploitability
The CVSS score of 9.4 marks this flaw as Critical. EPSS score of 6% indicates a moderate likelihood of exploitation in the wild, though the flaw is not listed in CISA KEV. Because the attack requires no prior authentication and relies on the publicly exposed GraphQL endpoint, the expected exploitation probability remains high, especially for publicly visible projects. Based on the description, it is inferred that an attacker can remotely exploit this vulnerability by sending crafted GraphQL directives from any external source with internet access.
OpenCVE Enrichment