HIGH
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Published May 14, 2026
8.7
HIGHCVSS 3.1
EPSS 0.40%
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with developer-role permissions to execute arbitrary JavaScript in other users' browsers due to improper input sanitization.
Affected products
-
- Version 16.4StatusaffectedConstraints<18.9.7
- Version 18.10StatusaffectedConstraints<18.10.6
- Version 18.11StatusaffectedConstraints<18.11.3
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 18.9.7, 18.10.6, 18.11.3 or above.
Weaknesses (1)
References (3)
- https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/ Release Notes
- https://gitlab.com/gitlab-org/gitlab/-/work_items/598646 Broken Link
- https://hackerone.com/reports/3697379 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released/ | Release Notes | |
| https://gitlab.com/gitlab-org/gitlab/-/work_items/598646 | Broken Link | |
| https://hackerone.com/reports/3697379 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published May 14, 2026
Updated May 15, 2026
Reserved Apr 30, 2026
Link CVE-2026-7481
CISA Vulnrichment
Updated May 14, 2026