Skip to content
GitLabCVE-2026-15217

GitLab: cross-site scripting

High8.7CVE-2026-15217 · Published Aug 12, 2026 · updated Aug 19, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 18.2, < 19.0.619.0.6
>= 19.1, < 19.1.419.1.4
>= 19.2, < 19.2.219.2.2
Details and references

More GitLab advisories

All GitLab
Advisory
GitLab: missing authorization
Medium4.3Aug 12
GitLab: missing authorization
Medium4.3Aug 12
GitLab: improper authorization
High8.5Aug 12
GitLab: improper authorization
Medium4.3Aug 12
GitLab: missing authorization
High7.1Aug 12
GitLab: cross-site scripting
High8.7Aug 12

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.