CISA flags active exploitation of critical GitLab vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency has added a maximum-severity GitLab flaw to its catalog of actively exploited vulnerabilities, warning that unauthenticated attackers can read sensitive data via the repository commits API. GitLab released patches in versions 19.3.2, 19.2.6, and 19.1, while security firm watchTowr reported internet-wide probing for unpatched servers. CISA urges all organizations to prioritize patching, with federal agencies required to secure systems within three days.
The flaw resides in the repository commits API, where weak authentication checks and path handling let unauthenticated requests retrieve arbitrary files, including credentials and secrets. GitLab's platform underpins development operations for a substantial share of large enterprises, so the exposure window between patch release and observed probing carries serious implications. Security firm watchTowr detected internet-wide scanning within a day of the fix, indicating threat actors move quickly against widely deployed DevOps infrastructure.
This is the fourth GitLab vulnerability CISA has added to its actively exploited catalog since late 2021. Earlier this year, the company addressed a separate high-severity issue allowing two-factor authentication bypass. The pattern highlights recurring challenges in securing collaboration platforms that hold sensitive code and authentication material, with federal agencies now bound to remediate within three days under binding operational guidance.
Because GitLab is embedded in software development pipelines across government and industry, exploitation could expose proprietary code, internal credentials, and customer data at scale. Organizations that delay patching may face breaches, while downstream users of compromised software could inherit risks through the supply chain. Federal agencies have a firm deadline, but private firms without similar mandates may remain vulnerable longer, potentially enabling credential theft and follow-on intrusions across multiple sectors.