Improper Restriction of Rendered UI Layers or Frames in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-3254
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to load unauthorized content into another user's browser.
The vulnerability exists due to improper restriction of rendered ui layers or frames in Mermaid sandbox when rendering Mermaid content under certain conditions. A remote user can supply crafted input to load unauthorized content into another user's browser.
User interaction is required.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-3254
GitLab Enterprise Edition - addressed in versions 18.9.6, 18.10.4, 18.11.1