Arbitrary JavaScript Execution Vulnerability in GitLab EE Software
CVE-2026-7481

8.7HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-7481?

A vulnerability in GitLab EE allows an authenticated user with developer-role permissions to execute arbitrary JavaScript code in the browsers of other users. This issue stems from improper input sanitization, compromising user security and privacy. All instances of GitLab EE from version 16.4 up to version 18.9.7, as well as specific versions 18.10 and 18.11, are affected. Users are advised to update to the latest secure version to mitigate potential exploitation.

Affected Version(s)

GitLab 16.4 < 18.9.7

GitLab 18.10 < 18.10.6

GitLab 18.11 < 18.11.3

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program
.