Improper Neutralization of Special Elements in Output Used by a Downstream Component in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-15077
Published: July 29, 2026 / Updated: July 30, 2026
GitLab Enterprise Edition
Gitlab Community Edition
Detailed vulnerability description
The vulnerability allows a remote user to access information from unauthorized projects.
The vulnerability exists due to improper neutralization of untrusted content in Duo Code Review when processing AI-assisted code review content. A remote user can submit crafted untrusted content to access information from unauthorized projects.