GitLab Flaw Under Active Attack as Exploits Hit the Wild
A critical GitLab vulnerability identified as CVE-2026-19478 with a CVSS score of 9.4 was exploited in the wild within days of its public disclosure, according to cybersecurity firm watchTowr. The flaw is a code injection vulnerability that allows unauthenticated attackers to modify or delete publicly available GitLab projects without requiring any credentials, user interaction, or special configuration. The issue affects multiple versions of both GitLab Community Edition and Enterprise Edition, and can be exploited through a GraphQL directive. GitLab has released patches in versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11 to address the vulnerability.
watchTowr successfully reproduced the vulnerability within minutes of its disclosure and detected active exploitation attempts against their honeypot infrastructure. The security firm emphasized that artificial intelligence is dramatically accelerating the timeline between vulnerability disclosure and exploitation, making traditional patch management cycles inadequate. Jake Knott, principal security researcher at watchTowr, warned that organizations waiting for their next scheduled patch cycle are putting themselves at significant risk in this new AI-powered threat landscape.
The impact of this vulnerability extends beyond simple project modifications. Attackers can completely remove repositories, manipulate merge records to falsify the application of security fixes, and even ban legitimate project maintainers from their own projects. This level of access could have severe consequences for software supply chain integrity and organizational operations. Organizations should search their web logs for requests containing the string '@gl_introduced' to identify potential scanning or exploitation attempts targeting their systems.
For organizations running internet-facing, self-hosted GitLab instances, immediate patching is critical. If upgrading to a patched version cannot be completed right away, temporary mitigation measures include restricting unauthenticated access to the endpoint "/api/graphql" or disabling public repository access entirely. This incident underscores the growing challenge of defending against AI-enhanced attacks that can identify and weaponize vulnerabilities at unprecedented speed, making rapid security response an operational imperative rather than a best practice.
Stay secure — stay Wavasec. 🔐