Impact
GitLab contains a cross‑site scripting flaw that allows an unauthenticated user to embed arbitrary JavaScript in content created with the editor because pasted HTML is not properly sanitized. The malicious script would execute in the web browser of any logged‑in user who views the affected content, thereby compromising confidentiality and integrity of that user’s session. Based on the description, it is inferred that an attacker could hijack a session or steal credentials if the injected script interacts with the browser’s storage or cookies, although these specific actions are not explicitly confirmed in the advisory.
Affected Systems
The vulnerability affects GitLab Community Edition and Enterprise Edition versions from 19.0 up to, but not including, 19.1.8; from 19.2 up to, but not including, 19.2.6; and from 19.3 up to, but not including, 19.3.2. All GitLab instances running these unsupported releases are vulnerable to the XSS flaw.
Risk and Exploitability
The CVSS base score of 4.7 indicates moderate risk, and the EPSS value of less than 1% suggests a very low predicted exploitation likelihood at present. The issue is not listed in the CISA KEV catalog and no public exploit has been reported. Attackers practically need to supply malicious content through the editor, then depend on a target user to view that content – the flaw therefore requires an unauthenticated user to create or influence content but targets authenticated users for the final execution.
OpenCVE Enrichment