PT-2026-65885 · Gitlab · Gitlab Ce/Ee
CVE-2026-3093
·
Published
2026-07-29
·
Updated
2026-08-17
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 14.0 through 19.0.4
GitLab CE/EE versions 19.1 through 19.1.2
GitLab CE/EE versions 19.2 through 19.2.0
Description
Improper sanitization of user-controlled input in the pagination page rendering mechanism allows a remote attacker to execute arbitrary JavaScript in another user's browser via a crafted URL. This issue is a Cross-Site Scripting (XSS) flaw, which occurs when an application includes untrusted data in a web page without proper validation or encoding.
Recommendations
Update GitLab CE/EE versions 14.0 through 19.0.4 to version 19.0.5.
Update GitLab CE/EE versions 19.1 through 19.1.2 to version 19.1.3.
Update GitLab CE/EE versions 19.2 through 19.2.0 to version 19.2.1.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Ce/Ee