Stored cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-2973
Published: March 25, 2026 / Updated: March 26, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in a user's browser.
The vulnerability exists due to improper sanitization of entity-encoded content in the Mermaid diagram renderer when rendering content. A remote user can inject malicious Mermaid diagrams containing encoded scripts, which when viewed by another user, execute arbitrary JavaScript in their browser.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-2973
Gitlab Community Edition - addressed in versions 18.8.7, 18.9.3, 18.10.1