Executive brief
GitLab has fixed a security flaw in its Service Desk feature, which allows users to manage customer support requests via email. An attacker could send a specially crafted email reply to impersonate the official GitLab Support Bot and inject unauthorized content into support tickets. This could be used to mislead users or provide false information within the platform's support system.
Technical details
A vulnerability exists in GitLab CE/EE due to improper neutralization of substitution characters (CWE-153) during email template processing. By sending a specially crafted Service Desk email reply, an attacker can bypass security controls to impersonate the GitLab Support Bot. This allows for the injection of arbitrary content into the Service Desk system. The attack requires network access and specific conditions to be met, and it is mitigated by a low CVSS score reflecting limited impact on confidentiality and availability. Patches are available in versions 18.10.8, 18.11.5, and 19.0.2.
Affected products
- GitLab GitLab Community Edition (CE) 15.9 to <18.10.8, 18.11 to <18.11.5, 19.0 to <19.0.2
- GitLab GitLab Enterprise Edition (EE) 15.9 to <18.10.8, 18.11 to <18.11.5, 19.0 to <19.0.2
Timeline
- 2026-06-10: patched: GitLab released versions 18.10.8, 18.11.5, and 19.0.2 to address the issue.
- 2026-06-11: disclosed: CVE-2026-9694 was published.