Improper Restriction of Rendered UI Layers or Frames in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-3254

 

Improper Restriction of Rendered UI Layers or Frames in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-3254

Published: May 18, 2026


Vulnerability identifier: #VU131661
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-3254
CWE-ID: CWE-1021
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to load unauthorized content into another user's browser.

The vulnerability exists due to improper restriction of rendered ui layers or frames in Mermaid sandbox when rendering Mermaid content under certain conditions. A remote user can supply crafted input to load unauthorized content into another user's browser.

User interaction is required.


Affected software

Gitlab Community Edition
GitLab Enterprise Edition

How to mitigate CVE-2026-3254

Install security update from vendor's website.

Gitlab Community Edition - addressed in versions 18.9.6, 18.10.4, 18.11.1
GitLab Enterprise Edition - addressed in versions 18.9.6, 18.10.4, 18.11.1

External References

Related Security Bulletins