MEDIUM
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Published Mar 25, 2026
5.4
MEDIUMCVSS 3.1
EPSS 0.29%
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.
Affected products
-
Affected
- ≥ 17.7, < 18.8.7
- ≥ 18.10, < 18.10.1
- ≥ 18.9, < 18.9.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.8.7, 18.9.3, 18.10.1 or above.
Weaknesses (1)
References (4)
- https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15809 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/591049 Broken Link
- https://hackerone.com/reports/3566802 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2026/03/25/patch-release-gitlab-18-10-1-released/ | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-15809 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/591049 | Broken Link | |
| https://hackerone.com/reports/3566802 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 25, 2026
Updated Mar 26, 2026
Reserved Feb 22, 2026
Link CVE-2026-2973
CISA Vulnrichment
Updated Mar 26, 2026
Red Hat
No data
GitHub
No data