Cross-site scripting in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-7377
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in other users' browsers.
The vulnerability exists due to improper input sanitization in customizable analytics dashboards when rendering dashboard content. A remote user can inject crafted script content to execute arbitrary JavaScript in other users' browsers.
User interaction is required to view the crafted content.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-7377
GitLab Enterprise Edition - addressed in versions 18.9.7, 18.10.6, 18.11.3