Executive brief
GitLab has fixed a security vulnerability in its Enterprise Edition that could allow an attacker to run malicious scripts in other users' browsers. This issue occurs within the customizable analytics dashboards, which are used by teams to track project performance and data. If exploited, an attacker could potentially steal session information or perform unauthorized actions on behalf of other users who view a compromised dashboard.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GitLab Enterprise Edition (EE) within the customizable analytics dashboards component. The flaw stems from improper input sanitization, which allows an authenticated attacker to inject and execute arbitrary JavaScript in the context of another user's browser session. Exploitation requires the victim to view a dashboard containing the malicious payload. The vulnerability affects versions 18.2 through 18.8.8, 18.9 through 18.9.4, and 18.10 through 18.10.2. GitLab has released patches in versions 18.8.9, 18.9.5, and 18.10.3 to address this issue.
Affected products
- GitLab GitLab Enterprise Edition (EE) 18.2 to 18.8.8, 18.9 to 18.9.4, 18.10 to 18.10.2
Timeline
- 2026-04-08: disclosed
- 2026-04-08: patched: Fixed in versions 18.10.3, 18.9.5, 18.8.9