9.1

CVE-2026-19478

Medienbericht

Improper Control of Generation of Code ('Code Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 18.2.0 < 18.11.11
Gitlab ≫ GitLab SwEdition enterprise Version >= 18.2.0 < 18.11.11
Gitlab ≫ GitLab SwEdition community Version >= 19.0.0 < 19.0.8
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.0.0 < 19.0.8
Gitlab ≫ GitLab SwEdition community Version >= 19.1.0 < 19.1.6
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.1.0 < 19.1.6
Gitlab ≫ GitLab SwEdition community Version >= 19.2.0 < 19.2.4
Gitlab ≫ GitLab SwEdition enterprise Version >= 19.2.0 < 19.2.4
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.51% 0.724
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
cve@gitlab.com 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
11.09.2026 19:43
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
24.08.2026 18:15
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
21.08.2026 10:22
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.08.2026 12:05
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
18.08.2026 10:47
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
17.08.2026 23:32
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-4-released/
Vendor Advisory
https://gitlab.com/gitlab-org/gitlab/-/work_items/611377
Not Applicable
https://hackerone.com/reports/3926431
Permissions Required