Impact
This vulnerability is a classic cross‑site scripting flaw that arises when the GitLab content editor accepts pasted HTML without proper sanitization. An unauthenticated user can embed arbitrary JavaScript that will run in the context of any logged‑in user who views the affected content. The flaw could allow attackers to hijack user sessions, steal session cookies, or perform actions on behalf of the user, compromising confidentiality and integrity of user accounts.
Affected Systems
The flaw affects GitLab Community Edition and Enterprise Edition versions from 19.0 up to, but not including, 19.1.8; from 19.2 up to, but not including, 19.2.6; and from 19.3 up to, but not including, 19.3.2. All GitLab instances running these unsupported releases are vulnerable.
Risk and Exploitability
The CVSS base score of 4.7 indicates moderate risk, and the EPSS value of less than 1% suggests a very low predicted exploitation likelihood at the moment. The vulnerability is not listed in the CISA KEV catalog, and there is no publicly listed exploit. Attackers would need to create or influence content in the editor to embed malicious code and rely on a target user viewing that content. Because the flaw requires an unauthenticated user to supply malicious input, it can be exploited in open or shared repositories without requiring privileged access.
OpenCVE Enrichment