
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1090 is a stored Cross-Site Scripting (XSS) vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE) affecting the markdown placeholder processing feature. It allows an authenticated user to inject arbitrary JavaScript into other users' browsers when the markdown_placeholders feature flag is enabled, due to improper sanitization of placeholder content. The vulnerability affects all GitLab CE/EE versions from 10.6 before 18.7.6, 18.8.x before 18.8.6, and 18.9.x before 18.9.2. It was disclosed and patched on March 11, 2026. The CVSS v3.1 base score is 8.7 (High) per GitLab's advisory, though NVD records a score of 5.4 (Medium) (GitLab Advisory, Feedly).
The root cause is improper neutralization of user-supplied input during web page generation (CWE-79) within GitLab's markdown processing pipeline. Specifically, when the markdown_placeholders feature flag is enabled, placeholder content embedded in markdown is not adequately sanitized before being rendered in the browser, allowing an attacker to embed malicious JavaScript payloads. The attack vector is network-based, requires low privileges (authenticated user), and requires user interaction (a victim must view the crafted markdown content). The changed scope indicates the impact extends beyond the vulnerable component itself. The vulnerability was reported by researcher yvvdwf via GitLab's HackerOne bug bounty program (GitLab Advisory).
Successful exploitation enables an authenticated attacker to execute arbitrary JavaScript in the browsers of other GitLab users who view the malicious markdown content. This can result in session token theft, account hijacking, unauthorized actions performed on behalf of victims, content defacement, and redirection to malicious sites. The changed scope means the impact can extend to systems and data accessible by compromised user accounts, including sensitive repository content, CI/CD secrets, and project data (GitLab Advisory, Feedly).
No public proof-of-concept exploit code is known to exist, and there is no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.019% (0.000190), indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker and victim interaction, which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Feedly).
markdown_placeholders feature flag enabled.<script> tags or event handler attributes).<script>, onerror=, onload=, javascript:) in issue, MR, wiki, or comment fields; access logs showing repeated views of specific pages by multiple users shortly after content creation.GitLab has released patched versions on March 11, 2026: 18.7.6, 18.8.6, and 18.9.2 for both CE and EE. All self-managed GitLab installations should be upgraded to one of these versions immediately. GitLab.com was already patched at time of disclosure; GitLab Dedicated customers do not need to take action. As a temporary workaround if immediate patching is not possible, disable the markdown_placeholders feature flag and restrict markdown editor access to trusted users only (GitLab Advisory).
The vulnerability received coverage from several security news outlets including SecurityOnline, CyberSecurityNews, and The Hacker Wire, which highlighted it as part of a broader GitLab security update addressing multiple high-severity issues including several Denial of Service vulnerabilities. Community discussion noted the wide version range affected (from GitLab 10.6 onward) and the dependency on the markdown_placeholders feature flag as a partial mitigating factor. The patch release was described as urgent given the High severity rating (SecurityOnline, CyberSecurityNews, The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."