Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.
Published: 2026-08-12
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

GitLab has an improper neutralization flaw that allows attacker‑controlled content to be rendered in an analytics dashboard table cell. This defect permits injection of JavaScript into rendered pages, enabling behaviors such as session hijacking, credential theft, data exfiltration, or defacement of web pages. The vulnerability is a classic cross‑site scripting flaw (CWE‑79).

Affected Systems

GitLab Community Edition and Enterprise Edition are affected. Versions prior to 19.0.6, prior to 19.1.4 for 19.1, and prior to 19.2.2 for 19.2 are vulnerable. All earlier releases from 18.2 onward are included in that scope.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. EPSS is not available, and the vulnerability is not listed in CISA KEV. Potential exploitation would involve accessing the web interface with privileges that allow creation or editing of analytics data, or opening a malicious link that contains crafted input. The web‑based attack vector and lack of additional prerequisites make the flaw likely to be exploitable by authenticated users with access to the dashboard component.

Generated by OpenCVE AI on August 12, 2026 at 22:17 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.0.6, 19.1.4, 19.2.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 19.0.6, 19.1.4, or 19.2.2 or later, which contains the remediation for the XSS flaw.
  • If an upgrade is delayed, disable or restrict access to the analytics dashboard to prevent injection of malicious content.
  • Apply application‑level input sanitization or CSP headers as a temporary mitigative measure to reduce XSS impact until the official patch can be installed.

Generated by OpenCVE AI on August 12, 2026 at 22:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-79
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-08-12T19:04:51.420Z

Reserved: 2026-07-09T08:05:28.649Z

Link: CVE-2026-15217

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-12T20:17:36.667

Modified: 2026-08-12T20:17:36.667

Link: CVE-2026-15217

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T22:30:09Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')