GitLab Flaw Exploited Within Days as Attackers Accelerate

TL;DR Gitlab Vulnerability
TOPICS
MORE LIKE THIS

This week’s TL;DR highlights two stories on risks in the systems organizations trust with their most sensitive assets: source code and credentials. Both show why internet-facing platforms and centralized security tools need rapid patching, strong architectural controls, and active monitoring.

The Hacker News reported that CVE-2026-19478 came under active exploitation within days of its public disclosure. The critical code-injection vulnerability carries a CVSS score of 9.4 and affects multiple GitLab Community Edition and Enterprise Edition releases.

Under certain conditions, an unauthenticated attacker can exploit GitLab’s GraphQL interface without user interaction. This could allow them to modify or delete public projects, rewrite repository data, falsify merge records and remove project maintainers.

The risk extends beyond losing source code. An attacker could alter project history or make it appear that a security fix had been applied when it had not. For organisations relying on GitLab as part of their software delivery process, that creates a direct threat to code integrity and operational continuity.

GitLab has released fixes in versions 18.11.11, 19.0.8, 19.1.6 and 19.2.4. Internet-facing, self-hosted instances should be updated immediately. Administrators should also search web logs for requests containing @gl_introduced. If patching cannot happen straight away, restrict unauthenticated access to /api/graphql or temporarily disable public repository access.

GitLab Vulnerability TL;DR

Attackers are already exploiting a critical GitLab vulnerability that requires no credentials or user interaction. Patch affected instances immediately and investigate GraphQL logs for signs of scanning or exploitation.

Dark Reading reported that a weakness in N-able Passportal’s browser extension could allow a malicious website to obtain the tokens associated with an organisation’s password vault.

The extension did not properly verify the origin of browser messages. Consequently, visiting a malicious website, or a legitimate page containing hostile advertising or an injected iframe, could expose access and refresh tokens.

The access token could potentially be used to retrieve stored credentials and time-based one-time passwords. Furthermore, the refresh token remained valid for up to 100 days, giving an attacker a route to regain access after the original access token expired.

N-able patched the browser-extension flaw shortly after researchers reported it. However, organisations should verify that every managed device has received the updated extension and investigate whether attackers may have exposed sensitive accounts before the patch.

The potential impact is particularly serious for managed service providers. A single MSP vault may contain privileged credentials for dozens of customer environments, turning one compromised account into a wider supply-chain incident. The researcher also questioned Passportal’s continued use of server-side credential decryption rather than end-to-end encryption.

Passportal TL;DR

A now-patched Passportal browser-extension flaw could expose complete credential vaults through malicious web content. Confirm that every device has received the update and review high-value accounts for possible exposure.

This week’s stories share a common thread: trusted platforms can create concentrated points of risk. Source-code repositories and password vaults need the same urgency, monitoring and access controls as any other critical infrastructure. Patching quickly, verifying updates across every endpoint and watching for signs of compromise remain essential. ThinScale helps organisations secure and manage the endpoint layer where many of these threats first reach users. Get in touch to find out how.

Ready to see it in action?