Database/Control plane, storage & DevOps
GitLab: stored XSS through merge request diff paths runs script in another user's session
Impact
Improper sanitization of path components in the merge request diff viewer lets an authenticated user get JavaScript to execute in another user's browser session, with a scope change in the CVSS vector. On a self-hosted GitLab that gates a GPU fleet's CI/CD, a targeted maintainer or admin session is the interesting one: script running there acts with that user's GitLab rights, which typically include pipeline configuration, CI variables and runner-facing secrets. The path from there to code and images that land on compute nodes is short, which is why an XSS in this system deserves more attention than its class usually gets.
Who can reach it
An authenticated GitLab user who can open a merge request with a crafted path, plus a victim who views that diff (UI:R). Anyone with push or fork-and-MR rights on a reachable project qualifies; on an internal instance that is any employee or tenant with an account.
What to do
Upgrade to 19.4.1, 19.3.3 or 19.2.7 depending on your branch; affected from 13.11. This is a GitLab application upgrade and service restart on the instance - no fleet-wide maintenance - and should be treated as routine patch-release hygiene. Nothing in the advisory suggests a configuration-level mitigation.
References
Related entries
- HPE iLO3/4/5: Remote unauthenticated denial of service against the management controllerCVE-2018-7093 · HPE iLO3/4/5High
- NAKIVO Backup & Replication: Unauthenticated absolute path traversal via getImageByPathCVE-2024-48248 · NAKIVO Backup & ReplicationHigh
- Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP): A large cluster of unauthenticated ModbusCVE-2024-48882 · Socomec DIRIS Digiware M-70 1.6.9 (Modbus TCP and Modbus RTU-over-TCP)High
- Ivanti Endpoint Manager (EPM): Auth bypass via alternate pathCVE-2026-1603 · Ivanti Endpoint Manager (EPM)High
- Pure Storage FlashArray Purity (management interface privilege bypass): An authenticated low-privileged user reachesCVE-2026-6444 · Pure Storage FlashArray Purity (management interface privilege bypass)High
- rclone (serve restic): Path validation in serve restic is incomplete, so an authenticated caller escapes the configuredCVE-2026-71309 · rclone (serve restic)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.