HarborGuard / CVE
Back to search
HIGHCVE-2026-1090Published Modified CNA GitLab

CVE-2026-1090: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.

Metrics

CVSS v3.1
8.7
Severity
HIGH
Fixed in
18.7.6
Affected Products
1

Fix available

18.7.618.8.618.9.2
Affected packages
  • GitLab / GitLab
    < 18.7.6 (from 10.6) · < 18.8.6 (from 18.8) · < 18.9.2 (from 18.9)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N