Tag: gitlab
-
Critical GitLab Flaw Lets Hackers Alter or Delete Public Projects
GitLab has patched two security flaws, including CVE-2026-19478, a critical code injection vulnerability that could allow unauthenticated attackers to remotely modify or delete public projects and user data. The disclosure adds to the growing list of GitLab vulnerabilities requiring prompt attention from organizations running self-managed instances. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/gitlab-patches-cve-2026-19478/
-
Critical GitLab Zero-Click Flaw Poses Mitigation Challenges
A lack of technical details could make it hard for organizations running self-managed GitLab versions to detect potential exploitation of CVE-2026-19478. First seen on darkreading.com Jump to article: www.darkreading.com/application-security/critical-gitlab-zero-click-flaw-mitigation-challenges
-
GitLab issues emergency patch for critical code-injection flaw
Researchers warn that unauthenticated attackers would be able to delete or modify publicly accessible projects. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/gitlab-emergency-patch-critical-code-injection/828151/
-
Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)
GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/18/gitlab-critical-code-injection-flaw-cve-2026-19478/
-
GitLab Patches Critical Unauthenticated GraphQL Vulnerability
GitLab patched a critical GraphQL flaw that let unauthenticated attackers remotely modify or delete public projects on self-managed servers. GitLab pushed out an emergency patch this week to address a critical flaw, tracked as CVE-2026-19478 (CVSS score of 9.4), that could let an attacker with zero credentials remotely modify or delete public projects and user…
-
Keine Anmeldung nötig: Gitlab-Lücke lässt Angreifer Softwareprojekte löschen
Aufgrund einer kritischen Sicherheitslücke können Angreifer ohne Anmeldung Gitlab-Projekte manipulieren oder löschen. Admins sollten zügig handeln. First seen on golem.de Jump to article: www.golem.de/news/keine-anmeldung-noetig-gitlab-luecke-laesst-angreifer-softwareprojekte-loeschen-2608-212022.html
-
Keine Anmeldung nötig: Gitlab-Lücke lässt Angreifer Softwareprojekte löschen
Aufgrund einer kritischen Sicherheitslücke können Angreifer ohne Anmeldung Gitlab-Projekte manipulieren oder löschen. Admins sollten zügig handeln. First seen on golem.de Jump to article: www.golem.de/news/keine-anmeldung-noetig-gitlab-luecke-laesst-angreifer-softwareprojekte-loeschen-2608-212022.html
-
Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects
GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, could allow an unauthenticated attacker to remotely modify or delete public projects and user data.The flaw, tracked as CVE-2026-19478, has been rated Critical by GitLab and assigned a CVSS score of…
-
Chainloop: Open-source evidence store and policy engine for the software supply chain
Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeline, picks up what … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/10/chainloop-open-source-supply-chain-security/
-
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Å»abka data leak offered for Euro5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Å»abka Polska. Å»abka Polska is Poland’s largest convenience store operator…
-
Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations. First seen on thecyberexpress.com Jump to article: thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
-
GitLab Users Urged to Patch After Research Reveals Critical RCE Chain
Researchers chained two Oj parser bugs to achieve GitLab RCE via Jupyter notebook diffs, affecting authenticated users on unpatched versions. Depthfirst researchers published a working remote code execution exploit for GitLab on July 24, chaining two memory corruption bugs in Oj, a Ruby JSON parser with a native C implementation, into full command execution inside…
-
GitLab RCE Flaws Allow Attackers to Execute Commands via Malicious Jupyter Notebooks
A critical remote code execution (RCE) vulnerability chain in GitLab’s Jupyter Notebook diff renderer. This issue is rooted in two long-standing memory safety vulnerabilities within the Oj Ruby JSON parser. The vulnerabilities impact both GitLab Community Edition and Enterprise Edition releases from version 15.2.0 through 19.0.1. They allow an authenticated project member to execute commands…
-
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab 18.11.3 server.An ordinary authenticated user triggers it by committing two crafted Jupyter notebooks and requesting their diff. The chain needs no administrator rights, continuous integration (CI) runner access, victim interaction First seen…
-
GitLab Patches 8 Vulnerabilities Affecting CE and EE Installations
GitLab has released critical security updates to address eight vulnerabilities in its Community Edition (CE) and Enterprise Edition (EE). Administrators are urged to upgrade immediately to versions 19.1.2, 19.0.4, or 18.11.7. The patch rollout on July 8, 2026, includes fixes for high-, medium-, and low-severity flaws affecting core functionalities such as wiki rendering, repository mirroring,…
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
GitLab-Studie zur KI-Softwareentwicklung – KI-Code wächst schneller als Governance
First seen on security-insider.de Jump to article: www.security-insider.de/gitlab-studie-ki-code-governance-traceability-a-756d92548ad404f84685561b14d4829d/
-
GitLab Patches Multiple Vulnerabilities Allowing Account Takeover
GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high”‘impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to GitLab 19.0.2, 18.11.5, or 18.10.8, as applicable, to fully mitigate these issues. GitLab Patches Multiple…
-
GitLab Patches Multiple Vulnerabilities Allowing Account Takeover
GitLab has released security updates for GitLab CE/EE and EE that patch multiple vulnerabilities, including several high”‘impact flaws that could lead to account takeover, data exposure, and denial of service if left unpatched. Administrators are strongly advised to upgrade to GitLab 19.0.2, 18.11.5, or 18.10.8, as applicable, to fully mitigate these issues. GitLab Patches Multiple…
-
Studie von GitLab – KI-generierter Code erzeugt schneller Sicherheitslücken, als er sie beseitigt
First seen on security-insider.de Jump to article: www.security-insider.de/ki-code-skalierbare-security-reviews-devops-a-d6842b922f23928b67accfeb2d881b65/
-
Expired domain leads to supply chain attack on node-ipc npm package
require(‘node-ipc’). The trojanized versions were designed to remain fully functional to avoid immediate detection, which together with other decisions attackers took, such as data exfiltration via DNS TXT, suggest stealthiness was a top priority.Once executed, the malicious code collects information about the host system, including operating system version, hostname, and environment variables. It then starts…
-
GitLab Security Flaw Allows Cross-Site Scripting and Unauthenticated DoS
GitLab has issued an urgent security update to neutralise a massive wave of vulnerabilities. Threat actors could exploit these newly disclosed flaws to silently hijack developer sessions or completely paralyze continuous integration pipelines with unauthenticated attacks. GitLab Security Flaw On May 13, 2026, GitLab released critical patch versions 18.11.3, 18.10.6, and 18.9.7 for both its…
-
GitLab Fixes Flaws That Could Allow Attackers to Hijack User Sessions
GitLab has released emergency security patches addressing 11 vulnerabilities across its Community Edition (CE) and Enterprise Edition (EE), including three high-severity flaws that could allow attackers to execute malicious code, forge requests, and steal user session tokens. On April 22, 2026, GitLab released versions 18.11.1, 18.10.4, and 18.9.6 for both CE and EE deployments. GitLab.com has already been…
-
Janela RAT Spreads via Fake MSI Installers, Malicious Extensions
Janela Remote Access Trojan (RAT) campaign using fake Windows MSI installers and malicious browser extensions to infiltrate financial networks and exfiltrate sensitive data. The latest Janela RAT samples are being distributed through public GitLab repositories, where attackers host MSI installation files disguised as legitimate software installers. Unsuspecting users in Chile, Colombia, and Mexico the campaign’s primary targets are lured into downloading these…
-
GitHub, GitLab Abused for Malware and Phishing Campaigns
Hackers are increasingly abusing trusted software development platforms GitHub and GitLab to host malware and credential phishing campaigns, making defensive detection significantly harder for enterprises. Because these Git-based platforms are deeply integrated into development and business workflows, organizations cannot simply block them at the network edge, giving threat actors a powerful, trusted delivery channel. GitHub…

