Executive brief
GitLab Enterprise Edition, a platform used for software development and version control, contains a security flaw in its Analytics Dashboard. An internal user with developer-level permissions could exploit this to run malicious code in the browser of another user, such as an administrator. This could lead to unauthorized access to sensitive data or the performance of actions on behalf of the victim.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GitLab Enterprise Edition (EE) due to improper input sanitization within the Analytics Dashboard component. An authenticated attacker with at least 'developer' role permissions can inject malicious payloads that execute arbitrary client-side code when a targeted user views the affected dashboard. The vulnerability is tracked as CWE-79 and carries a high CVSS score because it allows for session hijacking or unauthorized actions in the context of the victim's browser. GitLab has released patches in versions 18.10.8, 18.11.5, and 19.0.2 to address this issue.
Affected products
- GitLab GitLab Enterprise Edition 17.1 to < 18.10.8, 18.11 to < 18.11.5, 19.0 to < 19.0.2
Timeline
- 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2
- 2026-06-11: disclosed: CVE-2026-10087 published