Cross-site scripting in GitLab Enterprise Edition and Gitlab Community Edition - CVE-2026-84739
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary JavaScript in another user's browser session.
The vulnerability exists due to improper sanitization of path components in the merge request diff viewer when rendering merge request diffs. A remote user can provide crafted path components to execute arbitrary JavaScript in another user's browser session.
User interaction is required.
Affected software
Gitlab Community Edition
How to mitigate CVE-2026-84739
Gitlab Community Edition - addressed in versions 19.2.7, 19.3.3, 19.4.1