CVE-2026-1090
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-1090 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the markdown placeholder processing feature. It allows an authenticated user to inject arbitrary JavaScript into other users' browsers when the markdown_placeholders feature flag is enabled, due to improper sanitization of placeholder content. The vulnerability affects all GitLab CE/EE versions from 10.6 before 18.7.6, 18.8.x before 18.8.6, and 18.9.x before 18.9.2. It was disclosed and patched on March 11, 2026. The CVSS v3.1 base score is 8.7 (High) per GitLab's advisory, though NVD records a score of 5.4 (Medium) (GitLab Advisory, Feedly).

Technical details

The root cause is improper neutralization of user-supplied input during web page generation (CWE-79) within GitLab's markdown processing pipeline. Specifically, when the markdown_placeholders feature flag is enabled, placeholder content embedded in markdown is not adequately sanitized before being rendered in the browser, allowing an attacker to embed malicious JavaScript payloads. The attack vector is network-based, requires low privileges (authenticated user), and requires user interaction (a victim must view the crafted markdown content). The changed scope indicates the impact extends beyond the vulnerable component itself. The vulnerability was reported by researcher yvvdwf via GitLab's HackerOne bug bounty program (GitLab Advisory).

Impact

Successful exploitation enables an authenticated attacker to execute arbitrary JavaScript in the browsers of other GitLab users who view the malicious markdown content. This can result in session token theft, account hijacking, unauthorized actions performed on behalf of victims, content defacement, and redirection to malicious sites. The changed scope means the impact can extend to systems and data accessible by compromised user accounts, including sensitive repository content, CI/CD secrets, and project data (GitLab Advisory, Feedly).

Exploitability

No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.019% (0.000190), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker and victim interaction, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Feedly).

Exploitation steps

  1. Authenticate: Obtain valid credentials for any GitLab account on a vulnerable instance (versions 10.6–18.7.5, 18.8.0–18.8.5, or 18.9.0–18.9.1) with the markdown_placeholders feature flag enabled.
  2. Identify a markdown-rendering surface: Locate a GitLab feature that renders markdown with placeholder support, such as issue descriptions, merge request descriptions, wiki pages, or comments.
  3. Craft a malicious payload: Construct a markdown placeholder payload that embeds JavaScript, exploiting the lack of sanitization in placeholder content processing (e.g., a placeholder value containing <script> tags or event handler attributes).
  4. Submit the payload: Post or save the crafted markdown content in a location visible to target users (e.g., a shared issue, project wiki, or merge request).
  5. Wait for victim interaction: When another authenticated user views the page containing the malicious markdown, the injected JavaScript executes in their browser.
  6. Achieve objective: Use the executed JavaScript to steal session cookies, exfiltrate tokens, perform actions on behalf of the victim, or redirect them to an attacker-controlled site (GitLab Advisory, Feedly).

Indicators of compromise

  • Logs: GitLab application logs showing unusual markdown content submissions containing JavaScript keywords (<script>, onerror=, onload=, javascript:) in issue, MR, wiki, or comment fields; access logs showing repeated views of specific pages by multiple users shortly after content creation.
  • Network: Outbound requests from victim browsers to unexpected external domains following viewing of GitLab markdown content; unusual POST requests to attacker-controlled endpoints carrying session tokens or cookie data.
  • Application Behavior: Unexpected session invalidations or account actions (e.g., SSH key additions, token creation, permission changes) performed by users who recently viewed specific GitLab pages.
  • File System / Audit Logs: GitLab audit log entries showing privilege escalation, new personal access token creation, or SSH key additions by users who did not initiate those actions.

Mitigation and workarounds

GitLab has released patched versions on March 11, 2026: 18.7.6, 18.8.6, and 18.9.2 for both CE and EE. All self-managed GitLab installations should be upgraded to one of these versions immediately. GitLab.com was already patched at time of disclosure; GitLab Dedicated customers do not need to take action. As a temporary workaround if immediate patching is not possible, disable the markdown_placeholders feature flag and restrict markdown editor access to trusted users only (GitLab Advisory).

Community reactions

The vulnerability received coverage from several security news outlets including SecurityOnline, CyberSecurityNews, and The Hacker Wire, which highlighted it as part of a broader GitLab security update addressing multiple high-severity issues including several Denial of Service vulnerabilities. Community discussion noted the wide version range affected (from GitLab 10.6 onward) and the dependency on the markdown_placeholders feature flag as a partial mitigating factor. The patch release was described as urgent given the High severity rating (SecurityOnline, CyberSecurityNews, The Hacker Wire).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management