AI description
Automated description summarized from trusted sources.
CVE-2026-19619 describes a Cross-site Scripting (XSS) vulnerability found in GitLab CE/EE's Content Editor. This flaw stems from improper sanitization of HTML content that is pasted into the editor. Under specific conditions, this vulnerability could allow an unauthenticated user to execute arbitrary JavaScript within the context of a targeted user's session. The issue affects various versions of GitLab CE/EE, including those from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.
- Description
- GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
- Source
- cve@gitlab.com
- NVD status
- Analyzed
- Products
- gitlab
CVSS 3.1
- Type
- Secondary
- Base score
- 4.7
- Impact score
- 2.7
- Exploitability score
- 1.6
- Vector string
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity
- MEDIUM
- cve@gitlab.com
- CWE-79
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "5C9EE769-FE6C-426E-BF0B-233F4703C23C",
"versionEndExcluding": "19.1.8",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "119C424E-6742-4A26-9BD2-9BDFE2038354",
"versionEndExcluding": "19.1.8",
"versionStartIncluding": "19.0.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "4A6AAECA-E557-43EF-B109-B92D1281E48B",
"versionEndExcluding": "19.2.6",
"versionStartIncluding": "19.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "8598AF82-D212-4B5D-ABC3-C12C9B217BF3",
"versionEndExcluding": "19.2.6",
"versionStartIncluding": "19.2.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"matchCriteriaId": "198FF0EF-1A45-484F-9268-F7821E006BA8",
"versionEndExcluding": "19.3.2",
"versionStartIncluding": "19.3.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"matchCriteriaId": "03B1901F-AAF4-421E-B704-5345CB840DEF",
"versionEndExcluding": "19.3.2",
"versionStartIncluding": "19.3.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]