Impact
GitLab Enterprise Edition has an XSS flaw that allows an authenticated developer with developer‐role permissions to inject arbitrary scripts into pages viewed by other users. The vulnerability stems from improper sanitization of user‑supplied input during web page generation, which can enable arbitrary client‑side script execution in the victim’s browser session.
Affected Systems
GitLab EE versions 13.11 up to 18.11.6, 19.0 up to 19.0.3, and 19.1 up to 19.1.1 are impacted. These include all releases of the GitLab Enterprise Edition between those ranges. Users should verify their exact build and compare against the vendor's advisories to determine if a patch is required.
Risk and Exploitability
The CVSS base score of 8.7 denotes high severity. The EPSS score of <1% indicates a low likelihood of exploitation in the broader ecosystem. The flaw requires authenticated developer permissions, restricting the attacker pool to users with that role within an organization. The vulnerability is not listed in the CISA KEV catalog. Therefore, while the potential impact of arbitrary script execution exists, the actual risk depends on the organization’s developer access controls and the ability to patch.
OpenCVE Enrichment