CVE-2026-1090: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the markdownplaceholders feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user, when the markdownplaceholders feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-1090?
CVE-2026-1090 is classified as a moderate-severity cross-site scripting vulnerability.
How do I fix CVE-2026-1090?
To remediate CVE-2026-1090, upgrade GitLab to versions 18.7.6, 18.8.6, or 18.9.2.
Who is affected by CVE-2026-1090?
CVE-2026-1090 affects GitLab CE/EE versions from 10.6 up to, but not including, 18.7.6, 18.8.6, and 18.9.2.
What type of vulnerability is CVE-2026-1090?
CVE-2026-1090 is a cross-site scripting (XSS) vulnerability related to Markdown placeholder processing.
What can an attacker do with CVE-2026-1090?
An authenticated user could exploit CVE-2026-1090 to execute malicious scripts in the context of another user.