Junglewise Threat Intelligence

CVE-2026-10712: GitLab CE/EE XSS in Web IDE workbench asset handler

CVE-2026-10712 · Severity: high · CVSS 8 · Published 2026-06-25

Technologies: GitLab Community Edition (CE), GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab has fixed a security flaw in its Web IDE, a tool used by developers to edit code directly in their browser. An attacker could potentially run malicious scripts in another user's browser session, which could lead to the theft of sensitive session information or unauthorized actions on the user's behalf. This issue affects both the free and paid versions of GitLab and requires users to upgrade to the latest patched versions.

Technical details

A cross-site scripting (XSS) vulnerability exists in the GitLab Web IDE workbench asset handler due to improper path validation. An unauthenticated attacker can exploit this by tricking a user into visiting a specially crafted link, leading to the execution of arbitrary JavaScript in the context of the victim's browser session. The vulnerability is tracked as CVE-2026-10712 and has a CVSS score of 8.0 (High), characterized by high complexity and requiring user interaction. GitLab has released patches in versions 18.11.6, 19.0.3, and 19.1.1 to address the issue.

Affected products

  • GitLab GitLab Community Edition (CE) 18.10 to 18.11.5, 19.0 to 19.0.2, 19.1 to 19.1.0
  • GitLab GitLab Enterprise Edition (EE) 18.10 to 18.11.5, 19.0 to 19.0.2, 19.1 to 19.1.0

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6 to address the issue.
  • 2026-06-25: disclosed: Vulnerability details published via NVD and GitLab advisory.

References

Related threats