Description
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.
Published: 2026-05-14
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability exists in GitLab Enterprise Edition dashboards. An authenticated user can provide input that is not properly neutralized, which allows the execution of arbitrary JavaScript in other users’ browsers when they view the affected analytics dashboard. The primary impact is that malicious code can run in the victim’s browser context, constituting a classic Cross‑Site Scripting flaw (CWE‑79). Based on the description, it is inferred that the malicious script could affect the confidentiality, integrity, or availability of the affected users, but the specific consequences are not detailed in the CVE text.

Affected Systems

GitLab Enterprise Edition versions 18.7 up to but not including 18.9.7, 18.10 up to but not including 18.10.6, and 18.11 up to but not including 18.11.3 are vulnerable. These releases provide customizable analytics dashboards that can be exploited.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. The EPSS score is unavailable, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user who can create or edit a dashboard; once authenticated the attacker can inject JavaScript that will execute in any other authenticated user’s browser upon viewing the dashboard. The potential impact is limited to browser context and requires the victim to view the compromised page. Based on the description, it is inferred that a malicious insider or compromised legitimate account could abuse the flaw, but no public exploit is known.

Generated by OpenCVE AI on May 14, 2026 at 07:52 UTC.

Remediation

Vendor Solution

Upgrade to versions 18.9.7, 18.10.6, 18.11.3 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab Enterprise Edition to version 18.9.7, 18.10.6, 18.11.3 or later, which contains the fix for the XSS flaw.
  • If an upgrade cannot be performed immediately, restrict access to analytics dashboards to trusted administrators or temporarily disable custom dashboards until the patch is applied.
  • Audit and remove any custom analytics components that accept unsanitized user input, and verify that all dashboard widgets correctly sanitize input before deployment.

Generated by OpenCVE AI on May 14, 2026 at 07:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 16 May 2026 03:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

Thu, 14 May 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 May 2026 06:00:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-79
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-05-15T03:55:50.629Z

Reserved: 2026-04-29T07:34:11.142Z

Link: CVE-2026-7377

cve-icon Vulnrichment

Updated: 2026-05-14T13:18:33.667Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-14T06:16:25.267

Modified: 2026-05-16T03:33:03.577

Link: CVE-2026-7377

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-14T10:00:12Z

Weaknesses