CVE-2026-3093

EUVD-2026-50486
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due to improper sanitization of user-controlled input.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.7 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 14.43%
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
14.0.0 ≤
𝑥
< 19.0.5
gitlabgitlab
14.0.0 ≤
𝑥
< 19.0.5
gitlabgitlab
19.1.0 ≤
𝑥
< 19.1.3
gitlabgitlab
19.1.0 ≤
𝑥
< 19.1.3
gitlabgitlab
19.2.0
gitlabgitlab
19.2.0
𝑥
= Vulnerable software versions