Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-78252
GitLab vulnerability analysis and mitigation

Overview

CVE-2026-78252 is a Cross-Site Scripting (XSS) / Cross-Site Request Forgery (CSRF) vulnerability in GitLab CE/EE's Markdown JSON table renderer that allows an authenticated attacker to induce a targeted user to perform unintended state-changing HTTP requests. It affects all GitLab CE/EE versions from 15.3 before 19.1.8, versions 19.2 before 19.2.6, and versions 19.3 before 19.3.2. The vulnerability was published on September 16, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 8.2 (High) (GitHub Advisory, GitLab Patch Release).

Technical details

The root cause is improper sanitization of user-controlled data within GitLab's Markdown JSON table renderer (CWE-79: Improper Neutralization of Input During Web Page Generation). An authenticated attacker can craft malicious Markdown content containing a JSON table that, when rendered and viewed by a targeted user, causes that user's browser to execute unintended state-changing HTTP requests — effectively a CSRF-via-XSS attack vector. Exploitation requires user interaction (the victim must view the malicious content) and has high attack complexity, but no privileges beyond authentication are required on the attacker's part. The vulnerability was originally reported via HackerOne report #3917471 (GitHub Advisory, GitLab Issue).

Impact

Successful exploitation allows an authenticated attacker to cause a targeted user's browser to perform unauthorized state-changing HTTP requests on their behalf, such as modifying account settings, creating or deleting resources, or changing permissions within GitLab. The vulnerability has high confidentiality and integrity impact with low availability impact, and its changed scope means effects can extend beyond the directly vulnerable component. This could enable privilege escalation, unauthorized repository access, or account takeover depending on the actions triggered (GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation, as confirmed by NVD SSVC data indicating exploitation status of "none" (GitHub Advisory). The EPSS score is approximately 0.39%, placing it in the 33rd percentile for exploitation likelihood within 30 days. No threat actor attribution has been reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection signatures are available via Qualys (ID: 388702) and Nessus (ID: 346269).

Exploitation steps

  1. Authenticate to GitLab: The attacker must have a valid GitLab account on the target instance (any role that can create Markdown content such as issues, merge requests, wikis, or comments).
  2. Craft malicious Markdown: Create a Markdown JSON table payload that embeds unsanitized content exploiting the renderer's improper input handling — for example, injecting JavaScript or crafted HTML attributes within a JSON table structure that triggers a state-changing HTTP request (e.g., a form submission or fetch call) when rendered.
  3. Deliver the payload: Post the malicious Markdown content in a location visible to the target user, such as an issue comment, merge request description, wiki page, or project README.
  4. Wait for victim interaction: When the targeted user views the page containing the malicious Markdown table, their browser renders the content and executes the embedded payload, causing an unintended HTTP request (e.g., changing settings, adding SSH keys, or modifying permissions) on the victim's behalf.
  5. Achieve objective: Depending on the crafted request, the attacker may gain elevated access, exfiltrate data, or perform destructive actions within the victim's GitLab session (GitHub Advisory, GitLab Issue).

Indicators of compromise

  • Logs: GitLab application logs showing unexpected state-changing requests (POST/PUT/DELETE) originating from user sessions shortly after viewing specific issues, MRs, or wiki pages; unusual account setting changes or SSH key additions in audit logs.
  • Network: HTTP requests to GitLab API endpoints (e.g., /api/v4/users, /api/v4/projects) that do not match expected user workflows, particularly triggered immediately after page loads containing Markdown content.
  • Application: Presence of suspicious Markdown content in issues, merge requests, or wikis containing JSON table structures with embedded JavaScript, event handlers, or external URL references; unexpected changes to user profiles, SSH keys, or project membership.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 19.1.8 (for the 15.3–19.1.x branch), 19.2.6 (for the 19.2.x branch), and 19.3.2 (for the 19.3.x branch). All GitLab CE/EE administrators should upgrade to one of these versions immediately. As a supplementary measure, administrators can restrict Markdown/table creation capabilities to trusted users and educate users to exercise caution when viewing content from less-trusted sources within GitLab (GitLab Patch Release, GitHub Advisory).

Community reactions

Security news outlets including GBHackers and The Arabian Post covered the GitLab patch release, with The Arabian Post noting GitLab issued "urgent patches" for critical flaws in the same release cycle (GBHackers, Arabian Post). Coverage was primarily focused on the broader September 2026 GitLab patch release, which also addressed a critical path traversal vulnerability (CVE-2026-85706) that received more prominent attention. No notable individual researcher commentary specific to CVE-2026-78252 has been identified.

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-79708HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-78252HIGH8.2
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-86341MEDIUM4.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-8030MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026
CVE-2026-7514MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesSep 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management