PT-2026-56589 · Gitlab · Gitlab Ce/Ee

CVE-2026-13320

·

Published

2026-07-08

·

Updated

2026-07-13

CVSS v3.1

7.3

High

VectorAV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 15.7 through 18.11.6 GitLab CE/EE versions 19.0 through 19.0.3 GitLab CE/EE versions 19.1 through 19.1.1
Description An issue exists where improper sanitization of user-supplied input could allow an authenticated user to execute arbitrary scripts in another user's browser session. This is a Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or encoding, allowing a malicious script to execute in the victim's browser.
Recommendations Update GitLab CE/EE versions 15.7 through 18.11.6 to version 18.11.7. Update GitLab CE/EE versions 19.0 through 19.0.3 to version 19.0.4. Update GitLab CE/EE versions 19.1 through 19.1.1 to version 19.1.2.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09565
BIT-GITLAB-2026-13320
CVE-2026-13320

Affected Products

Gitlab Ce/Ee