Cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-15217
Published: August 13, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary script in a victim's browser.
The vulnerability exists due to cross-site scripting in analytics dashboards table field configuration when rendering user-controlled values in table cell content. A remote user can inject crafted content to execute arbitrary script in a victim's browser.
User interaction is required.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-15217
Gitlab Community Edition - addressed in versions 19.0.6, 19.1.4, 19.2.2