Junglewise Threat Intelligence

CVE-2026-6073: GitLab Enterprise Edition cross-site scripting due to improper sanitization

CVE-2026-6073 · Severity: high · CVSS 8.7 · Published 2026-05-14

Technologies: GitLab Enterprise Edition (EE). Vendors: GitLab.

Executive brief

GitLab Enterprise Edition, a platform used by organizations to manage software development and source code, contains a security vulnerability that allows an attacker to run malicious code in the browsers of other users. By tricking a colleague or administrator into viewing a specific page, an attacker could potentially steal sensitive session information or perform actions on behalf of that user. This issue has been resolved in the latest security updates, and organizations should patch their GitLab instances immediately.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in GitLab EE due to improper input sanitization. An authenticated attacker can inject malicious scripts into the application that are subsequently executed in the browsers of other users who view the affected content. The vulnerability is tracked as CWE-79 and carries a high CVSS score because it involves a scope change (S:C), potentially allowing the attacker to access sensitive session tokens or perform unauthorized actions as the victim. The issue affects versions 18.7 through 18.11.2 and has been patched in versions 18.9.7, 18.10.6, and 18.11.3.

Affected products

  • GitLab GitLab Enterprise Edition (EE) 18.7 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
  • 2026-05-14: disclosed: CVE-2026-6073 was published.

References

Related threats