CVE-2026-6896
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute…
Does this matter?
Lower severity and a low EPSS score (0.40%). Track it; it rarely justifies an emergency change on its own.
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.40% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/Vendor Advisory
- https://gitlab.com/gitlab-org/gitlab/-/work_items/597887Broken Link
- https://hackerone.com/reports/3682085Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.