VDB
GCVE-110-NCSC-2026-303
GCVE-110-NCSC-2026-303
Advisory PublishedCVSS 7.1/10
GitLab versions 18.2 to before 18.11.11, 19.0 to before 19.0.8, 19.1 to before 19.1.6, and 19.2 to before 19.2.4 contained a vulnerability allowing unauthenticated users to remotely modify or delete public projects and user data via a GraphQL directive.
Weaknesses (CWE)
CWE-94Improper Control of Generation of Code ('Code Injection')CWE-352Cross-Site Request Forgery (CSRF)
Risk Scores
CVSS 3.1
7.1/10
High · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| GitLab | vers:unknown/* | — | — |
Aliases
Browse GCVE Records
3,045 records in the GCVE database · Updated September 6, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.