Junglewise Threat Intelligence

CVE-2026-7377: GitLab EE stored XSS in customizable analytics dashboards

CVE-2026-7377 · Severity: high · CVSS 8.7 · Published 2026-05-14

Technologies: GitLab Enterprise Edition (EE). Vendors: GitLab.

Executive brief

GitLab Enterprise Edition contains a security flaw in its customizable analytics dashboards that could allow a malicious user to run unauthorized code in the browsers of other team members. This could lead to the theft of sensitive session information or unauthorized actions being performed on behalf of other users. Organizations should update to the latest patched versions of GitLab to protect their development environment and user accounts.

Technical details

A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in GitLab EE's customizable analytics dashboards due to improper input sanitization. An authenticated attacker with network access can inject malicious scripts into a dashboard that, when viewed by another user, executes arbitrary JavaScript in the context of that user's session. This vulnerability has a CVSS score of 8.7, reflecting its potential for high confidentiality and integrity impact through session hijacking or unauthorized API requests. The issue affects versions 18.7 through 18.11.2 and has been remediated in versions 18.9.7, 18.10.6, and 18.11.3.

Affected products

  • GitLab GitLab Enterprise Edition (EE) 18.7 to < 18.9.7, 18.10 to < 18.10.6, 18.11 to < 18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.11.3, 18.10.6, and 18.9.7 to address the issue.
  • 2026-05-14: disclosed: Vulnerability publicly disclosed and CVE-2026-7377 assigned.

References

Related threats