Threat actors began exploiting a critical GitLab vulnerability roughly two days after public disclosure, attack surface management company WatchTowr warns.
Tracked as CVE-2026-19478 (CVSS score of 9.4), the code injection flaw was fixed on August 17, when GitLab warned that it could be used remotely without authentication.
“GitLab fixed an issue that, under certain conditions, could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive,” GitLab said.
The fixes were introduced in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 19.2.4, 19.1.6, 19.0.8, and 18.11.11.
On August 18, WatchTowr warned that the flaw could easily be replicated, urging users to update their self-managed copies as soon as possible. As a mitigation, they should limit unauthenticated access to the /api/graphql endpoint or remove access to the public repository entirely.
“Although no public exploit code is available, WatchTowr was able to reproduce the vulnerability within minutes of its discovery, armed only with advisory details and a patch. AI-enabled attackers are unlikely to be far behind,” the company said Security Week at that time.
On Wednesday, WatchTowr warned that its honeypot network had already caught the first exploit attempts in the wild targeting CVE-2026-19478.
“Organizations that have not yet been patched should search web logs for requests containing ‘@gl_introduced’ and look for signs of samples or exploit attempts,” the company said.
The narrow remediation window, fueled by the severity of the bug and the use of AI, is the new reality of vulnerability reproduction and exploitation, says WatchTowr Principal Security Researcher Jake Knott.
“The newly disclosed code injection vulnerability allows an unauthorized attacker to delete publicly available GitLab projects and rewrite their state by completely deleting repositories, tampering with merge records, or disallowing maintainers in a single HTTP request without any credentials, user interaction, or obfuscated configuration,” Knott said.
According to Mondoo co-founder and CSO Patrick Münch, the new GitLab flaw could easily fuel the next wave of supply chain attacks, given that it can be used to falsify any merge records.
“Think about what that means. In every supply chain worm we’ve tracked this year, attackers had to bypass code review because it was harder to fake an approval than avoid it. This makes it free. An attacker can make a malicious change appear to have been reviewed and signed off by someone your team trusts, your pipeline builds and sends it down the chain, and your own audit log swears that everything was legitimate. Deleting a repo costs you a bad afternoon. Building trust in it costs you every subsequent release,” Munch said.
Related: CISA demands immediate patching of Microsoft, VMware, Apple exploited vulnerabilities
Related: 943 fixes released with the August 2026 Oracle Security Update
Related: Chrome, Firefox updates fix dozens of vulnerabilities
Related: Trivi, not LiteLLM, is behind the compromise with 2,500 organizations