HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Published Apr 22, 2026
8.0
HIGHCVSS 3.1
EPSS 0.36%
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.
Affected products
-
Affected
- ≥ 16.1.0, < 18.9.6
- ≥ 18.10, < 18.10.4
- ≥ 18.11, < 18.11.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.9.6, 18.10.4, 18.11.1 or above.
Weaknesses (1)
References (4)
- https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/ Release NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25042 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/595332 Broken Link
- https://hackerone.com/reports/3574642 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2026/04/22/patch-release-gitlab-18-11-1-released/ | Release NotesVendor Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25042 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/595332 | Broken Link | |
| https://hackerone.com/reports/3574642 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Apr 22, 2026
Updated Apr 22, 2026
Reserved Mar 31, 2026
Link CVE-2026-5262
CISA Vulnrichment
Updated Apr 22, 2026
Red Hat
No data
GitHub
No data