GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: unsanitized Markdown JSON table content induces state-changing requests as a targeted user

CVSS 8.2CVE-2026-78252Control plane, storage & DevOpscurated

Impact

Improper sanitization of user-controlled data in the Markdown JSON table renderer lets an authenticated user craft content that, when viewed, induces a targeted user's browser into unintended state-changing requests against GitLab. On a self-hosted GitLab that drives fleet CI/CD, the targeted user is often a maintainer or admin, and state-changing requests in their session mean pipeline, runner, token and membership changes - which is a path into whatever those pipelines deploy on the GPU fleet. GitLab rates it with a scope change and high confidentiality and integrity impact. The advisory does not describe the specific requests an attacker can force.

Who can reach it

Network, authenticated attacker (any user who can post Markdown), plus user interaction - the victim must view the crafted content. Affects all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

What to do

Upgrade self-managed GitLab to 19.3.2, 19.2.6 or 19.1.8 depending on your branch. Standard GitLab patch release: application upgrade and service restart, no node reboot, though it is a maintenance window for everything that depends on the instance's CI. GitLab.com is already patched.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.