Arbitrary JavaScript Execution Vulnerability in GitLab EE Software
CVE-2026-7481
8.7HIGH
What is CVE-2026-7481?
A vulnerability in GitLab EE allows an authenticated user with developer-role permissions to execute arbitrary JavaScript code in the browsers of other users. This issue stems from improper input sanitization, compromising user security and privacy. All instances of GitLab EE from version 16.4 up to version 18.9.7, as well as specific versions 18.10 and 18.11, are affected. Users are advised to update to the latest secure version to mitigate potential exploitation.
Affected Version(s)
GitLab 16.4 < 18.9.7
GitLab 18.10 < 18.10.6
GitLab 18.11 < 18.11.3
References
CVSS V3.1
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program