Junglewise Threat Intelligence

CVE-2026-1606: GitLab CE/EE improper input validation in Snippets

CVE-2026-1606 · Severity: medium · CVSS 4.3 · Published 2026-06-25

Technologies: GitLab CE, GitLab EE. Vendors: GitLab.

Executive brief

GitLab has fixed a security issue in its Community and Enterprise editions where authenticated users could hide or manipulate content within Snippets. Snippets are used by developers to share small pieces of code or text. While this does not lead to data theft, it could be used to mislead other users or conceal malicious code within shared resources.

Technical details

An improper input validation vulnerability (CWE-94) exists in GitLab CE/EE's Snippets component. An authenticated attacker with network access can exploit this flaw to conceal content within a Snippet, potentially bypassing visual inspection or security reviews. The vulnerability affects versions 14.8 through 18.11.5, 19.0.x before 19.0.3, and 19.1.0. The issue has been addressed in versions 18.11.6, 19.0.3, and 19.1.1. The CVSS score of 4.3 reflects that while the attack is easy to execute (low complexity, network vector), it only impacts integrity (low) without affecting confidentiality or availability.

Affected products

  • GitLab GitLab CE/EE 14.8 to <18.11.6, 19.0 to <19.0.3, 19.1 to <19.1.1

Timeline

  • 2026-06-24: patched: GitLab released versions 19.1.1, 19.0.3, 18.11.6
  • 2026-06-25: advisory: NVD published CVE-2026-1606 detail

References

Related threats