CVE-2020-13271
GitLab vulnerability analysis and mitigation

Overview

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in GitLab CE/EE versions through 13.0.1, specifically affecting the blobs API. The vulnerability was reported on August 13, 2019, and was officially patched in the security release on May 27, 2020. This security issue was assigned the identifier CVE-2020-13271 (GitLab Security, CVE Mitre).

Technical details

The vulnerability allowed for the execution of arbitrary JavaScript code through the repository blobs API. The exploit could be triggered when visiting blob APIs through the browser, specifically involving .svg files. The attack vector involved creating a repository with a specially crafted SVG file and accessing it through the Raw Blob Content API (HackerOne Report).

Impact

The vulnerability could lead to complete account takeover if a user was tricked into visiting a malicious page. An attacker could gain access to the victim's entire profile, including the ability to use both internal and external APIs. The attacker could also recover the X-CSRF-Token from the GraphQL explorer, enabling them to make authenticated requests on behalf of the victim (HackerOne Report).

Exploitability

The vulnerability could be exploited by creating a malicious SVG file in a repository and tricking users into visiting the specific blob API endpoint. The attack could be facilitated through various methods, including embedding the malicious link in an issue or performing a redirect from an external website (HackerOne Report).

Mitigation and workarounds

The vulnerability was patched in GitLab versions 13.0.1, 12.10.7, and 12.9.8. GitLab strongly recommended that all installations running affected versions be upgraded to the latest version immediately (GitLab Security).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-75871CRITICAL9.6
  • GitLab logoGitLab
  • gitlab
NoYesAug 27, 2026
CVE-2026-18252HIGH8.1
  • GitLab logoGitLab
  • gitlab
NoYesAug 26, 2026
CVE-2026-77801MEDIUM6.5
  • GitLab logoGitLab
  • gitlab-workhorse-ce-fips-18.10
NoYesAug 26, 2026
CVE-2026-3035MEDIUM5.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 26, 2026
CVE-2026-7487LOW3.5
  • GitLab logoGitLab
  • gitlab
NoYesAug 26, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management