CVE-2026-5262

EUVD-2026-25042
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 22%
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
16.1.0 ≤
𝑥
< 18.9.6
gitlabgitlab
16.1.0 ≤
𝑥
< 18.9.6
gitlabgitlab
18.10.0 ≤
𝑥
< 18.10.4
gitlabgitlab
18.10.0 ≤
𝑥
< 18.10.4
gitlabgitlab
18.11.0
gitlabgitlab
18.11.0
𝑥
= Vulnerable software versions