Skip to content
GitLabCVE-2026-78252

GitLab: cross-site scripting

High8.2CVE-2026-78252 · Published Sep 16, 2026

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.

GitLab advisory

Affected versions

PackageAffectedFixed in
GitLab
Product
>= 15.3, < 19.1.819.1.8
>= 19.2, < 19.2.619.2.6
>= 19.3, < 19.3.219.3.2
Details and references

More GitLab advisories

All GitLab
Advisory
GitLab: improper access control
Medium4.4Sep 16
GitLab: improper authorization
High8.5Sep 16
GitLab: improper authorization
Medium4.3Sep 16
GitLab: missing authorization
Medium4.3Sep 16
GitLab: cross-site scripting
Medium4.7Sep 16
GitLab: denial of service
High7.5Sep 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.