Database/Control plane, storage & DevOps
GitLab CE/EE: stored XSS in analytics dashboard pagination controls
Impact
User-controlled data rendered into an analytics dashboard's pagination controls is not neutralised, so an attacker with a low-privileged GitLab account can get script to run in the browser of another user who views the dashboard. On a self-managed GitLab that drives the fleet's CI/CD, the victim's session is the interesting part: it can reach project settings, CI variables, registry credentials and cluster deploy tokens - the material that pipelines use to push images and manifests onto GPU nodes. The CVSS vector records a changed scope with high confidentiality and integrity impact, and user interaction is required. Exploitation is conditional; GitLab describes it as occurring 'under certain conditions' without stating which.
Who can reach it
An authenticated GitLab user with enough access to place data into an analytics dashboard, plus a second user who views that dashboard. Requires user interaction.
What to do
Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 depending on your branch; versions from 18.2 onward are affected. This is a package upgrade and service restart on the GitLab host - no node drain and no runner-side change. GitLab.com is already patched.
References
Related entries
- GitLab CE/EE: stored XSS in analytics dashboard table cell renderingCVE-2026-15217 · GitLab CE/EE (analytics dashboard table cell rendering)High
- Sigstore Fulcio: OIDC discovery follows cross-host redirects and leaks ServiceAccount tokensCVE-2026-49478 · Sigstore Fulcio (OIDC discovery HTTP client, cross-host redirects)High
- Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64): An out-of-boundsCVE-2026-55732 · Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS, L-PAD and LIP-ME201C (through 8.4.18, LINX-A64)High
- Netty: OpenSSL client path silently skips TLS hostname verification on Java 25+CVE-2026-62243 · Netty io.netty:netty-handler (SslProvider.OPENSSL client-side hostname verification)High
- Pure Storage FlashArray Purity (data path information exposure): Insufficient filtering on certain data paths exposesCVE-2026-6445 · Pure Storage FlashArray Purity (data path information exposure)High
- SeaweedFS S3 API: raw OIDC JWT bypasses IAM role trust policy and grants that role's bucket accessCVE-2026-77298 · SeaweedFS S3 API (direct OIDC bearer token to IAM role mapping)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.