GitLab EE Flow Restriction Bypass Vulnerability for Developer Role Users

Vulnerability

A vulnerability exists in GitLab EE versions 18.7 prior to 18.10.7, 18.11 prior to 18.11.4, and 19.0 prior to 19.0.1. When foundational flows were enabled at the group level, this vulnerability allowed an authenticated user with developer-role permissions to bypass flow restrictions under certain conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized bypassing of flow restrictions, potentially allowing users to manipulate workflows or processes inappropriately.

Added: May 28, 2026, 3:40 AM
Updated: May 28, 2026, 3:40 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
5.2
remediation
7.7
relevance
9.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.