Cross-site scripting in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2026-19619
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the context of a targeted user\'s session.
The vulnerability exists due to improper sanitization of pasted HTML content in the Content Editor when rendering pasted HTML content. A remote attacker can provide crafted HTML content to execute arbitrary JavaScript in the context of a targeted user\'s session.
User interaction is required.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2026-19619
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2