Cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-6896

 

Cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-6896

Published: July 8, 2026


Vulnerability identifier: #VU137123
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N]
CVE-ID: CVE-2026-6896
CWE-ID: CWE-79
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary scripts in another user's browser session.

The vulnerability exists due to improper sanitization of user-supplied input in the vulnerability evidence table renderer when rendering user-supplied content. A remote user can inject specially crafted input to execute arbitrary scripts in another user's browser session.

User interaction is required for the victim to view the rendered content.


Affected software

GitLab Enterprise Edition
Gitlab Community Edition

How to mitigate CVE-2026-6896

Install security update from vendor's website.

GitLab Enterprise Edition - addressed in versions 18.11.7, 19.0.4, 19.1.2
Gitlab Community Edition - addressed in versions 18.11.7, 19.0.4, 19.1.2

External References

Related Security Bulletins