CVE-2025-8279

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
28/07/2025
Last modified:
11/08/2025

Description

Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:gitlab:language_server:*:*:*:*:*:*:*:* 7.6.0 (including) 7.30.0 (excluding)


References to Advisories, Solutions, and Tools