Impact
GitLab contains a code injection flaw that allows an attacker to construct malicious GraphQL directives. When processed, the directive enables modification or removal of public projects and user information. The vulnerability is classified as CWE‑94 and can be exploited remotely without authentication, directly compromising data integrity.
Affected Systems
The issue affects all public installations of GitLab from version 18.2 up to but not including 18.11.11, from 19.0 up to but not including 19.0.8, from 19.1 up to but not including 19.1.6, and from 19.2 up to but not including 19.2.4.
Risk and Exploitability
The CVSS score of 9.4 marks this flaw as Critical. EPSS data is not available, but the flaw is not listed in the CISA KEV catalog. Because the attack requires no prior authentication and utilizes the publicly exposed GraphQL endpoint, the expected likelihood of exploitation remains high, especially for high‑visibility public projects.
OpenCVE Enrichment