Sceawere

Vulnerability Detail

CVE-2026-84739UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GitLab Stored XSS in MR Diff Viewer

Vulnerability Metadata

Severity
High
Score / CVSS
8.7
Creation Date
15h ago
Vendor
GitLab
Product
GitLab
Attack Type
CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Attack Complexity
LOW

Narrative and Response

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user's browser session due to improper sanitization of path components in the merge request diff viewer.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.7",
  "pubDate": "2026-09-29T10:17:12.820Z",
  "pubdate": "2026-09-29T10:17:12.820Z",
  "executiveSummary": "This vulnerability is a Stored Cross-Site Scripting (XSS) flaw identified within the merge request diff viewer of GitLab CE/EE. The issue arises from insufficient sanitization of path components, allowing an authenticated attacker to inject and execute arbitrary JavaScript code within the context of a victim's browser session.\nThe vulnerability affects GitLab CE/EE versions 13.11 through 19.2.7, 19.3 through 19.3.3, and 19.4 before 19.4.1. Successful exploitation grants an attacker the ability to execute malicious scripts under the security context of the victim, potentially leading to unauthorized actions, session hijacking, or exfiltration of sensitive information.\nThe risk is significant due to the nature of stored XSS, which can be triggered automatically when a user views the compromised merge request. Exploitation requires the attacker to have at least authenticated access to the GitLab instance. Organizations are advised to update to the patched versions immediately to mitigate potential exploitation attempts against their internal and external GitLab environments.",
  "technicalDetails": "The vulnerability is rooted in an improper input sanitization mechanism within the merge request diff viewer component of GitLab CE/EE. Specifically, the application failed to adequately validate and sanitize path components provided during the merge request process. This failure allows an authenticated attacker to inject crafted malicious JavaScript payloads into fields that are subsequently rendered unsafely in the browser of any user who accesses the affected merge request.\nThe attack flow begins with an authenticated user manipulating a specific path component associated with a merge request diff. By embedding a malicious JavaScript payload within the path, the attacker causes the application to store this payload in the GitLab database. When a target user, such as a project maintainer or reviewer, navigates to the impacted merge request diff view, the GitLab frontend dynamically retrieves the stored content. Because the application fails to perform proper output encoding or sanitization, the browser interprets the attacker's input as executable code rather than plain text.\nThe execution of the JavaScript occurs within the victim's authenticated browser session. This provides the attacker with a variety of post-exploitation capabilities, including but not limited to: accessing the victim's session cookies, performing actions on the GitLab instance on behalf of the victim (e.g., merging code, modifying project settings, or deleting repositories), exfiltrating sensitive data visible to the victim, or redirecting the user to a malicious external site. The impact is limited to the privileges held by the victim's account; however, if a highly privileged user is targeted, the entire instance integrity could be compromised.\nThe scope of affected versions includes all GitLab CE/EE instances from version 13.11 up to 19.2.7, versions 19.3 through 19.3.2, and 19.4.0. The vulnerability is strictly an application-layer issue residing in the server-side processing and client-side rendering logic of the diff viewer. Since the payload is stored persistently, no constant network connectivity is required by the attacker after the initial injection; the malicious code resides on the server and executes on-demand whenever the view is triggered by an unsuspecting user.\nTo remediate, GitLab implemented stricter sanitization routines for path components to ensure that inputs are neutralized before being stored or reflected in the UI, effectively neutralizing the XSS vector."
}
CVE-2026-84739: GitLab Stored XSS in MR Diff Viewer (HIGH Severity, CVSS: 8.7) | Sceawere