CVE-2026-19619

Published Sep 16, 2026

Last updated 5 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-19619 describes a Cross-site Scripting (XSS) vulnerability found in GitLab CE/EE's Content Editor. This flaw stems from improper sanitization of HTML content that is pasted into the editor. Under specific conditions, this vulnerability could allow an unauthenticated user to execute arbitrary JavaScript within the context of a targeted user's session. The issue affects various versions of GitLab CE/EE, including those from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2.

Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
Source
cve@gitlab.com
NVD status
Analyzed
Products
gitlab

Risk scores

CVSS 3.1

Type
Secondary
Base score
4.7
Impact score
2.7
Exploitability score
1.6
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Severity
MEDIUM

Weaknesses

cve@gitlab.com
CWE-79

Social media

Hype score
Not currently trending

Configurations