
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-78252 is a Cross-Site Scripting (XSS) / Cross-Site Request Forgery (CSRF) vulnerability in GitLab CE/EE's Markdown JSON table renderer that allows an authenticated attacker to induce a targeted user to perform unintended state-changing HTTP requests. It affects all GitLab CE/EE versions from 15.3 before 19.1.8, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is improper sanitization of user-controlled data within GitLab's Markdown JSON table renderer (CWE-79: Improper Neutralization of Input During Web Page Generation). An authenticated attacker can craft malicious Markdown content containing a JSON table that, when rendered and viewed by a targeted user, causes that user's browser to execute unintended state-changing HTTP requests — effectively a CSRF-via-XSS attack vector. Exploitation requires user interaction (the victim must view the malicious content) and has high attack complexity, but no privileges beyond authentication are required on the attacker's part. The vulnerability was originally reported via HackerOne report #3917471 (GitHub Advisory, GitLab Issue).
Successful exploitation allows an authenticated attacker to cause a targeted user's browser to perform unauthorized state-changing HTTP requests on their behalf, such as modifying account settings, creating or deleting resources, or changing permissions within GitLab. The vulnerability has high confidentiality and integrity impact with low availability impact, and its changed scope means effects can extend beyond the directly vulnerable component. This could enable privilege escalation, unauthorized repository access, or account takeover depending on the actions triggered (GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation, as confirmed by NVD SSVC data indicating exploitation status of "none" (GitHub Advisory). The EPSS score is approximately 0.39%, placing it in the 33rd percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (ID: 388702) and Nessus (ID: 346269).
/api/v4/users, /api/v4/projects) that do not match expected user workflows, particularly triggered immediately after page loads containing Markdown content.GitLab has released patched versions addressing this vulnerability: 19.1.8 (for the 15.3–19.1.x branch), 19.2.6 (for the 19.2.x branch), and 19.3.2 (for the 19.3.x branch). All GitLab CE/EE administrators should upgrade to one of these versions immediately. As a supplementary measure, administrators can restrict Markdown/table creation capabilities to trusted users and educate users to exercise caution when viewing content from less-trusted sources within GitLab (GitLab Patch Release, GitHub Advisory).
Security news outlets including GBHackers and The Arabian Post covered the GitLab patch release, with The Arabian Post noting GitLab issued "urgent patches" for critical flaws in the same release cycle (GBHackers, Arabian Post). Coverage was primarily focused on the broader September 2026 GitLab patch release, which also addressed a critical path traversal vulnerability (CVE-2026-85706) that received more prominent attention. No notable individual researcher commentary specific to CVE-2026-78252 has been identified.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"