GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: stored XSS via pasted HTML in the Content Editor

CVSS 4.7CVE-2026-19619Control plane, storage & DevOpscurated

Impact

Pasted HTML content in the GitLab Content Editor is not sanitized properly, letting an unauthenticated actor plant markup that runs JavaScript in a targeted user's session when that user views the content. Against a self-hosted GitLab that drives cluster CI/CD, the value of the flaw is whatever the victim's session can do - if the victim is a maintainer, that includes pipeline and variable access. Exploitation needs user interaction and the advisory rates attack complexity high, so this is a targeted-phishing-shaped bug rather than mass exploitation. Impact is limited to the browser session; nothing here touches the GitLab host itself.

Who can reach it

Unauthenticated over the network to place the content, but a targeted GitLab user must then view it in their browser. User interaction is required.

What to do

Upgrade self-managed GitLab to 19.1.8, 19.2.6, or 19.3.2 (affected from 19.0). Package upgrade and service restart on the GitLab host - no cluster impact.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.