Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
History

Mon, 11 Aug 2025 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Gitlab language Server
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:gitlab:language_server:*:*:*:*:*:*:*:*
Vendors & Products Gitlab language Server

Mon, 28 Jul 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Jul 2025 14:15:00 +0000

Type Values Removed Values Added
Description Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
Title Missing Authentication for Critical Function in GitLab Language Server
First Time appeared Gitlab
Gitlab gitlab-language-server
Weaknesses CWE-306
CPEs cpe:2.3:a:gitlab:gitlab-language-server:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab-language-server
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2025-07-28T14:23:37.024Z

Reserved: 2025-07-28T13:04:22.709Z

Link: CVE-2025-8279

cve-icon Vulnrichment

Updated: 2025-07-28T14:23:04.834Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-28T14:15:28.857

Modified: 2025-08-11T18:59:40.013

Link: CVE-2025-8279

cve-icon Redhat

No data.