Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.
Published: 2026-09-29
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting that permits execution of arbitrary JavaScript in another user’s browser context
Action: Apply Patch
AI Analysis

Impact

The vulnerability is an instance of improper sanitization of path components in the merge request diff viewer. An authenticated attacker can inject and execute arbitrary JavaScript, which allows the attacker to run code in the victim’s browser session. This can compromise confidentiality and integrity by stealing session cookies, performing actions on the victim’s behalf, or delivering further malicious payloads, potentially leading to account takeover.

Affected Systems

GitLab Community and Enterprise Editions from 13.11 through 19.2.6, 19.3 through 19.3.2, and 19.4 through 19.4.0 are affected. The issue is fixed in GitLab 19.2.7, 19.3.3, 19.4.1 and later releases.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity, and the EPSS score of less than 1% suggests a very low probability of exploitation at present. This flaw is not listed in the CISA KEV catalog. An attacker would need authenticated access to the GitLab instance and the ability to view or manipulate merge request diffs; typically the vulnerability is triggered by visiting a crafted URL that renders the diff view and allows arbitrary JavaScript to be injected.

Generated by OpenCVE AI on September 29, 2026 at 16:06 UTC.

Remediation

Vendor Solution

Upgrade to versions 19.2.7, 19.3.3, 19.4.1 or above.


OpenCVE Recommended Actions

  • Upgrade GitLab to version 19.2.7, 19.3.3, 19.4.1 or later to apply the vendor fix
  • Restrict access to the merge request diff viewer so that only trusted users with legitimate development or review responsibilities can view diffs, limiting exposure to the vulnerable code path
  • Consider enabling a web‑application firewall or a stricter Content‑Security‑Policy header to block injected scripts as a secondary defense while the upgrade is in progress

Generated by OpenCVE AI on September 29, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Description GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.
Title Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-79
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 8.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-09-29T15:04:40.962Z

Reserved: 2026-09-02T08:35:53.127Z

Link: CVE-2026-84739

cve-icon Vulnrichment

Updated: 2026-09-29T15:04:37.168Z

cve-icon NVD

Status : Received

Published: 2026-09-29T10:17:12.820

Modified: 2026-09-29T15:17:30.183

Link: CVE-2026-84739

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T16:15:14Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')