Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
History

Mon, 28 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Description Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
Title Missing Authentication for Critical Function in GitLab Language Server
First Time appeared Gitlab
Gitlab gitlab-language-server
Weaknesses CWE-306
CPEs cpe:2.3:a:gitlab:gitlab-language-server:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab-language-server
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-07-28T14:04:28.764Z

Updated: 2025-07-28T14:23:37.024Z

Reserved: 2025-07-28T13:04:22.709Z

Link: CVE-2025-8279

cve-icon Vulnrichment

Updated: 2025-07-28T14:23:04.834Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-28T14:15:28.857

Modified: 2025-07-29T14:14:29.590

Link: CVE-2025-8279

cve-icon Redhat

No data.