Cybersecurity · 139 views
Critical GitLab flaw allows attackers to delete and modify public repos
GitLab has fixed a critical vulnerability that could allow unauthenticated attackers to perform unauthorized modifications inside code repositories or to completely delete them with a single HTTP request.
AI Summary
GitLab has released patches for a critical vulnerability that could let unauthenticated attackers delete or modify public code repositories with a single HTTP request. The flaw, tracked as CVE‑2026‑19478, is a code‑injection issue via the GraphQL directive and was reported privately through GitLab’s bug‑bounty program on HackerOne. The same releases also fix a high‑risk cross‑site request forgery (CSRF) flaw. Security researchers at watchTowr said they could reproduce the vulnerability within minutes of the advisory, using only the patch and advisory details, and warned that AI‑enabled attackers could likely craft an exploit quickly.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedMore from Cybersecurity
Continue reading recent Cybersecurity coverage
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API DrainingContinue reading
- OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior DisclosureContinue reading
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted LinkContinue reading
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon ExtortionsContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow