Gitlab · Gitlab Ce/Ee · CVE-2026-19619
**Name of the Vulnerable Software and Affected Versions**
GitLab CE/EE versions 19.0 through 19.1.7
GitLab CE/EE versions 19.2 through 19.2.5
GitLab CE/EE versions 19.3 through 19.3.1
**Description**
Improper sanitization of pasted HTML content in the Content Editor could allow an unauthenticated user to execute arbitrary JavaScript within the session of a targeted user.
**Recommendations**
Update GitLab CE/EE versions 19.0 through 19.1.7 to version 19.1.8.
Update GitLab CE/EE versions 19.2 through 19.2.5 to version 19.2.6.
Update GitLab CE/EE versions 19.3 through 19.3.1 to version 19.3.2.