HIGHCVE-2026-1090Published Modified CNA GitLab
CVE-2026-1090: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.
Metrics
- CVSS v3.1
- 8.7
- Severity
- HIGH
- Fixed in
- 18.7.6
- Affected Products
- 1
Fix available
18.7.618.8.618.9.2
Affected packages
- GitLab / GitLab< 18.7.6 (from 10.6) · < 18.8.6 (from 18.8) · < 18.9.2 (from 18.9)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N