Impact
The vulnerability is an instance of improper sanitization of path components in the merge request diff viewer. An authenticated attacker can inject and execute arbitrary JavaScript, which allows the attacker to run code in the victim’s browser session. This can compromise confidentiality and integrity by stealing session cookies, performing actions on the victim’s behalf, or delivering further malicious payloads, potentially leading to account takeover.
Affected Systems
GitLab Community and Enterprise Editions from 13.11 through 19.2.6, 19.3 through 19.3.2, and 19.4 through 19.4.0 are affected. The issue is fixed in GitLab 19.2.7, 19.3.3, 19.4.1 and later releases.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. This flaw is not listed in the CISA KEV catalog. An attacker would need authenticated access to the GitLab instance and the ability to view or manipulate merge request diffs; typically the vulnerability is triggered by visiting a crafted URL that renders the diff view and allows arbitrary JavaScript to be injected.
OpenCVE Enrichment