CVE 8.7 HIGH

Missing Authentication for Critical Function in GitLab Language Server_CVE-2025-8279

8.7 / 10
HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Description

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

Basic Information

ID CVE-2025-8279
Source GitLab
Published Jul 28, 2025 at 14:04
Modified Jul 28, 2025 at 14:23

Affected Product

Vendor GitLab
Product GitLab Language Server
Version 7.6.0
Affected Versions GitLab GitLab Language Server 7.6.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.