PT-2026-56589 · Gitlab · Gitlab Ce/Ee
CVE-2026-13320
·
Published
2026-07-08
·
Updated
2026-07-13
CVSS v3.1
7.3
High
| Vector | AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 15.7 through 18.11.6
GitLab CE/EE versions 19.0 through 19.0.3
GitLab CE/EE versions 19.1 through 19.1.1
Description
An issue exists where improper sanitization of user-supplied input could allow an authenticated user to execute arbitrary scripts in another user's browser session. This is a Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or encoding, allowing a malicious script to execute in the victim's browser.
Recommendations
Update GitLab CE/EE versions 15.7 through 18.11.6 to version 18.11.7.
Update GitLab CE/EE versions 19.0 through 19.0.3 to version 19.0.4.
Update GitLab CE/EE versions 19.1 through 19.1.1 to version 19.1.2.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Ce/Ee