Database/Control plane, storage & DevOps
GitLab: unsanitized HTML in the CI job modal lets a developer-role user escalate privileges
Impact
HTML rendered in the CI job modal is not sanitized properly, so a user holding only the developer role can plant content that executes in the session of whoever opens that modal. The CVSS vector is scope-changed with high confidentiality, integrity, and availability, meaning the attacker can end up acting as a higher-privileged account. On a self-hosted GitLab driving a GPU fleet, that account controls pipeline definitions, runner registration tokens, and the credentials CI jobs use — the route from a developer-level foothold to controlling what executes on the GPU nodes. Exploitation needs a victim to view the affected modal, so it is not unattended. Affected: 19.2 before 19.2.2.
Who can reach it
An authenticated user with developer-role permissions on a project, plus a more privileged user who opens the CI job modal for the poisoned job.
What to do
Upgrade to GitLab 19.2.2. Control-plane package upgrade and service restart; brief GitLab outage, no effect on nodes already running jobs.
References
Related entries
- Woodpecker CI: pipeline authors can pick any ServiceAccount for their build podsCVE-2026-61549 · Woodpecker CI Kubernetes backend (backend_options.kubernetes.serviceAccountName)Critical
- Jenkins Remoting: JEP-200 deserialization filter bypassed via fallback class resolution on the controllerCVE-2026-70426 · Jenkins Remoting (JEP-200 deserialization class filter, fallback resolution path)Critical
- Crossplane package manager (cosign signature verification via ImageConfig): SUPPLY CHAIN, TIME-OF-CHECK TO TIME-OF-USENCVD-2026-055-crossplane-package-manager-cosig · Crossplane package manager (cosign signature verification via ImageConfig)Critical
- Ceph CephX: malleable, unauthenticated tickets let a low-privilege key be forged into Manager, MDS or OSD accessCVE-2025-30156 · Ceph CephX authentication protocol (unauthenticated AES-128-CBC ticket encryption)High
- Ceph CephX (authentication protocol): A tenant holding one low-privilege CephX client key ends up with cluster-wideNCVD-2025-016-ceph-cephx-authentication-protoc · Ceph CephX (authentication protocol)High
- GlusterFS (brick, server-rpc-fops.c): Multiple stack buffer overflows from fixed-size alloca() allocations in the brickCVE-2018-10907 · GlusterFS (brick, server-rpc-fops.c)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.