CVE-2026-1090

EUVD-2026-11180
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
GitLabCNA
8.7 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
10.6.0 ≤
𝑥
< 18.7.6
gitlabgitlab
10.6.0 ≤
𝑥
< 18.7.6
gitlabgitlab
18.8.0 ≤
𝑥
< 18.8.6
gitlabgitlab
18.8.0 ≤
𝑥
< 18.8.6
gitlabgitlab
18.9.0 ≤
𝑥
< 18.9.2
gitlabgitlab
18.9.0 ≤
𝑥
< 18.9.2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
gitlab
sid
vulnerable