Cross-site scripting in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-6335
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code in another user's browser session.
The vulnerability exists due to improper sanitization in Banzai markdown sanitizer when rendering crafted markdown content. A remote user can inject crafted script content to execute arbitrary code in another user's browser session.
User interaction is required to view the crafted content.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-6335
GitLab Enterprise Edition - update to 18.11.3