PT-2026-52196 · Gitlab · Gitlab
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 18.10 through 18.11.5
GitLab CE/EE versions 19.0 through 19.0.2
GitLab CE/EE versions 19.1 through 19.1.0
Description
An issue exists in the Web IDE workbench where improper path validation allows an unauthenticated attacker to execute arbitrary JavaScript in a user's browser session via a crafted asset request. This stored Cross-Site Scripting (XSS) can expose CI/CD secrets and source code by gaining access to developer sessions.
Recommendations
Update versions 18.10 through 18.11.5 to 18.11.6.
Update versions 19.0 through 19.0.2 to 19.0.3.
Update versions 19.1 through 19.1.0 to 19.1.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab