Database/Control plane, storage & DevOps
GitLab CE/EE: stored XSS in analytics dashboard table cell rendering
Impact
The same analytics dashboard component fails to neutralise user-controlled values rendered into table cells, giving a second stored cross-site scripting path. A low-privileged user can plant a value that executes in the session of whoever opens the dashboard, and that session carries the victim's rights over CI variables, tokens and project configuration on a self-managed GitLab that feeds the GPU fleet's pipelines. It is fixed in the same releases as CVE-2026-15216, so it is one upgrade, not two. GitLab again qualifies exploitation as possible 'under certain conditions' without describing them.
Who can reach it
An authenticated GitLab user who can supply the rendered value, and a second user who views the affected dashboard. Requires user interaction.
What to do
Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 for your branch - all versions from 18.2 are affected. Package upgrade plus GitLab service restart; the same patch release also fixes CVE-2026-15216.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.