Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
Published: 2026-09-16
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑site Scripting
Action: Patch
AI Analysis

Impact

GitLab contains a cross‑site scripting flaw that allows an unauthenticated user to embed arbitrary JavaScript in content created with the editor because pasted HTML is not properly sanitized. The malicious script would execute in the web browser of any logged‑in user who views the affected content, thereby compromising confidentiality and integrity of that user’s session. Based on the description, it is inferred that an attacker could hijack a session or steal credentials if the injected script interacts with the browser’s storage or cookies, although these specific actions are not explicitly confirmed in the advisory.

Affected Systems

The vulnerability affects GitLab Community Edition and Enterprise Edition versions from 19.0 up to, but not including, 19.1.8; from 19.2 up to, but not including, 19.2.6; and from 19.3 up to, but not including, 19.3.2. All GitLab instances running these unsupported releases are vulnerable to the XSS flaw.

Risk and Exploitability

The CVSS base score of 4.7 indicates moderate risk, and the EPSS value of less than 1% suggests a very low predicted exploitation likelihood at present. The issue is not listed in the CISA KEV catalog and no public exploit has been reported. Attackers practically need to supply malicious content through the editor, then depend on a target user to view that content – the flaw therefore requires an unauthenticated user to create or influence content but targets authenticated users for the final execution.

Generated by OpenCVE AI on September 18, 2026 at 12:40 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.1.8, 19.2.6, 19.3.2 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to a patched release (19.1.8, 19.2.6, 19.3.2 or later).
  • Remove or sanitize any existing pasted HTML content that may contain malicious code in the content editor to ensure no stored XSS payloads remain.
  • Monitor application logs for script execution attempts and review user activity for anomalies.

Generated by OpenCVE AI on September 18, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Wed, 16 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-79
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-16T17:36:42.232Z

Reserved: 2026-08-12T14:11:39.176Z

Link: CVE-2026-19619

cve-icon Vulnrichment

Updated: 2026-09-16T17:36:32.191Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-16T07:16:36.600

Modified: 2026-09-28T15:21:18.480

Link: CVE-2026-19619

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T12:45:08Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')