GPU VulnDB

Database/Control plane, storage & DevOps

GitLab: stored XSS through merge request diff paths runs script in another user's session

CVSS 8.7CVE-2026-84739Control plane, storage & DevOpscurated

Impact

Improper sanitization of path components in the merge request diff viewer lets an authenticated user get JavaScript to execute in another user's browser session, with a scope change in the CVSS vector. On a self-hosted GitLab that gates a GPU fleet's CI/CD, a targeted maintainer or admin session is the interesting one: script running there acts with that user's GitLab rights, which typically include pipeline configuration, CI variables and runner-facing secrets. The path from there to code and images that land on compute nodes is short, which is why an XSS in this system deserves more attention than its class usually gets.

Who can reach it

An authenticated GitLab user who can open a merge request with a crafted path, plus a victim who views that diff (UI:R). Anyone with push or fork-and-MR rights on a reachable project qualifies; on an internal instance that is any employee or tenant with an account.

What to do

Upgrade to 19.4.1, 19.3.3 or 19.2.7 depending on your branch; affected from 13.11. This is a GitLab application upgrade and service restart on the instance - no fleet-wide maintenance - and should be treated as routine patch-release hygiene. Nothing in the advisory suggests a configuration-level mitigation.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.