← Back to CVE search

CVE-2026-3093

GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user-s browser via a crafted URL, due to improper sanitization of user-controlled input.

CVSS 4.7EPSS 0.23800000000000002%Risk 0.48
View source
Published
2026-07-29 20:17:03
Affected versions
<19.0.5, <19.1.3, <19.2.1
Type
Web application
Last modified
2026-08-03 14:04:02
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N