Back

MEDIUM

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

Published Mar 25, 2026

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.

Affected products

Remediation

Vendor solution

Upgrade to versions 18.8.7, 18.9.3, 18.10.1 or above.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitLab
Published Mar 25, 2026
Updated Mar 26, 2026
Reserved Feb 22, 2026

CISA Vulnrichment

Updated Mar 26, 2026

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitLab
Published Mar 25, 2026
Updated Mar 26, 2026

GitHub

No data