Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user-s browser via a crafted URL, due to improper sanitization of user-controlled input.
CVSS 4.7EPSS 0.23800000000000002%Risk 0.48
View source- Published
- 2026-07-29 20:17:03
- Affected versions
- <19.0.5, <19.1.3, <19.2.1
- Type
- Web application
- Last modified
- 2026-08-03 14:04:02
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N