Detects GitLab instances where the GraphQL API endpoint lacks CSRF token validation on mutation operations. An unauthenticated attacker can execute arbitrary GraphQL mutations on behalf of any logged-in user who visits a malicious page — creating personal access tokens, modifying repositories, or changing CI/CD settings. Versions 17.10.0–18.8.6, 18.9.0–18.9.2, and 18.10.0 are affected.
Is your app exploitable through CVE-2026-3857?
Scan your domain free