GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: stored XSS in analytics dashboard table cell rendering

CVE-2026-15217Control plane, storage & DevOpscurated

Impact

The same analytics dashboard component fails to neutralise user-controlled values rendered into table cells, giving a second stored cross-site scripting path. A low-privileged user can plant a value that executes in the session of whoever opens the dashboard, and that session carries the victim's rights over CI variables, tokens and project configuration on a self-managed GitLab that feeds the GPU fleet's pipelines. It is fixed in the same releases as CVE-2026-15216, so it is one upgrade, not two. GitLab again qualifies exploitation as possible 'under certain conditions' without describing them.

Who can reach it

An authenticated GitLab user who can supply the rendered value, and a second user who views the affected dashboard. Requires user interaction.

What to do

Upgrade self-managed GitLab to 19.2.2, 19.1.4 or 19.0.6 for your branch - all versions from 18.2 are affected. Package upgrade plus GitLab service restart; the same patch release also fixes CVE-2026-15216.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.