Intel

AIKIDO-2026-851525

gitlab-ce is vulnerable to Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS)CVE-2026-19619 Published 3 days ago

47

Medium Risk

This Affects:

OSgitlab-ce
19.0.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

The Content Editor does not adequately sanitize pasted HTML. An unauthenticated attacker can craft content that executes arbitrary JavaScript in a targeted user's session. The fix sanitizes pasted HTML in the Content Editor before it is rendered.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gitlab-ce is vulnerable to Cross-Site Scripting (XSS) in versions 19.0.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform