Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.
Published: 2026-08-12
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab includes an improper neutralization of user-controlled data in pagination controls of an analytics dashboard component, creating a classic cross-site scripting vulnerability (CWE-79). An attacker could inject malicious scripts that execute in the browser context of any user who views the affected dashboard, facilitating theft of credentials, session hijacking, or the execution of arbitrary commands on the client side. The flaw directly jeopardizes confidentiality and integrity of user data and the overall trustworthiness of the GitLab web interface.

Affected Systems

GitLab Community Edition and Enterprise Edition from version 18.2 up to, but not including, 19.0.6, from 19.1 up to, but not including, 19.1.4, and from 19.2 up to, but not including, 19.2.2 are susceptible. All other supported releases are considered secure.

Risk and Exploitability

The CVSS score of 8.7 classifies this as high severity, although the EPSS score is currently unavailable, meaning no published exploitation data exists. It is not listed in the CISA KEV catalog. The likely attack vector is through the web UI where a user engages with the analytics dashboards; an attacker can craft malicious pagination input that will be rendered unsanitized. The absence of an EPSS score does not diminish the potential impact for organizations that have exposed the vulnerable interface.

Generated by OpenCVE AI on August 12, 2026 at 22:17 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 19.0.6, 19.1.4, 19.2.2 or later and apply all security patches for the affected component.
  • Restart all GitLab services to complete the upgrade and ensure the new code is in use.
  • Configure a strict Content Security Policy that blocks inline script execution to mitigate any residual XSS vectors.

Generated by OpenCVE AI on August 12, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-79
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-12T19:04:46.419Z

Reserved: 2026-07-09T08:05:23.804Z

Link: CVE-2026-15216

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:36.513

Modified: 2026-08-12T20:17:36.513

Link: CVE-2026-15216

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T00:00:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')