
Cloud Vulnerability DB
コミュニティ主導の脆弱性データベース
CVE-2026-78252 is a Cross-Site Scripting (XSS) / Cross-Site Request Forgery (CSRF) vulnerability in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The flaw stems from improper sanitization of user-controlled data in the Markdown JSON table renderer, allowing an authenticated attacker to induce a targeted user to perform unintended state-changing HTTP requests. It was published on September 16, 2026, with patches released the same day. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, GitLab Patch Release).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically arising from insufficient sanitization of user-supplied input within GitLab's Markdown JSON table renderer (GitHub Advisory). An authenticated attacker can craft a malicious Markdown JSON table that, when rendered and viewed by a victim user, causes the victim's browser to issue unintended state-changing HTTP requests on their behalf — effectively a stored XSS/CSRF hybrid attack. Exploitation requires user interaction (the victim must view the malicious content) and has high attack complexity, but no privileges beyond authentication are required on the attacker's part. The vulnerability was originally reported via HackerOne report #3917471 (GitHub Advisory).
Successful exploitation allows an authenticated attacker to cause a targeted GitLab user's browser to execute unauthorized state-changing HTTP requests without the victim's knowledge or consent, such as modifying repository settings, changing user permissions, creating or deleting resources, or altering access controls (GitHub Advisory). The CVSS scoring reflects high confidentiality and integrity impact with low availability impact and a changed scope, indicating that the effects can extend beyond the directly vulnerable component. In environments where privileged users (e.g., administrators or project owners) are targeted, the impact could include full project or instance compromise through privilege escalation via unauthorized actions.
There is no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been observed as of the publication date (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, requiring user interaction. The EPSS score is approximately 0.39%, placing it in the 33rd percentile for exploitation probability within 30 days. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/api/v4/users, /api/v4/projects/:id/members) that correlate with page views of attacker-controlled Markdown content.javascript: URIs, or embedded <script> tags or encoded equivalents.GitLab has released patched versions addressing this vulnerability: 19.1.8, 19.2.6, and 19.3.2. All GitLab CE/EE installations running versions from 15.3 through the unpatched releases should upgrade immediately to the appropriate fixed version (GitLab Patch Release, GitHub Advisory). As a temporary workaround where immediate patching is not possible, administrators should restrict Markdown content creation (issues, MRs, wikis) to trusted users only, and educate users to be cautious when viewing content from less-trusted contributors within GitLab.
The vulnerability received coverage from security news outlets including GBHackers and The Arabian Post, which reported on the broader GitLab patch release that addressed multiple flaws (GBHackers, The Arabian Post). Tenable published a Nessus detection plugin (ID 346269) and Qualys added detection (ID 388702) shortly after disclosure, indicating prompt uptake by the vulnerability management community (GitHub Advisory). No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified beyond standard vulnerability tracking coverage.
ソース: このレポートは AI を使用して生成されました
無料の脆弱性評価
9つのセキュリティドメインにわたるクラウドセキュリティプラクティスを評価して、リスクレベルをベンチマークし、防御のギャップを特定します。
パーソナライズされたデモを見る
"私が今まで見た中で最高のユーザーエクスペリエンスは、クラウドワークロードを完全に可視化します。"
"Wiz を使えば、クラウド環境で何が起こっているかを 1 つの画面で確認することができます"
"Wizが何かを重要視した場合、それは実際に重要であることを私たちは知っています。"