PT-2026-52196 · Gitlab · Gitlab

·

CVE-2026-10712

·

Published

2026-06-24

·

Updated

2026-06-29

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.10 through 18.11.5 GitLab CE/EE versions 19.0 through 19.0.2 GitLab CE/EE versions 19.1 through 19.1.0
Description An issue exists in the Web IDE workbench where improper path validation allows an unauthenticated attacker to execute arbitrary JavaScript in a user's browser session via a crafted asset request. This stored Cross-Site Scripting (XSS) can expose CI/CD secrets and source code by gaining access to developer sessions.
Recommendations Update versions 18.10 through 18.11.5 to 18.11.6. Update versions 19.0 through 19.0.2 to 19.0.3. Update versions 19.1 through 19.1.0 to 19.1.1.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08984
BIT-GITLAB-2026-10712
CVE-2026-10712

Affected Products

Gitlab