#VU124599 Cross-Site Request Forgery (CSRF) in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-3857
Published: March 25, 2026
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to execute arbitrary GraphQL mutations on behalf of authenticated users.
The vulnerability exists due to insufficient CSRF protection in the GLQL API when handling requests. A remote attacker can trick an authenticated user into clicking a malicious link to execute arbitrary GraphQL mutations on behalf of the user.