SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-3093

MEDIUM · CVSS 4.7 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

GitLab CE/EE versions prior to 19.0.5, 19.1.3, and 19.2.1 are vulnerable to a cross-site scripting (XSS) flaw that allows attackers to execute arbitrary JavaScript in a victim's browser through crafted URLs, stemming from improper input sanitization. This vulnerability poses a medium risk, particularly for organizations using affected versions of GitLab, as it could lead to unauthorized actions or data exposure in user sessions. Administrators should prioritize patching to mitigate potential exploitation risks.

CVE
CVE-2026-3093
Severity
MEDIUM
CVSS
4.7
EPSS
0.24%
Java GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input.

Related CVEs

Other vulnerabilities affecting the same vendor(s)