CVE-2026-1606: Improper Control of Generation of Code ('Code Injection') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.11.6 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.0.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 19.1.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1606?
The severity of CVE-2026-1606 is rated medium with a score of 4.3.
How do I fix CVE-2026-1606?
To fix CVE-2026-1606, upgrade to GitLab CE/EE version 18.11.6 or newer, 19.0.3 or newer, or 19.1.1 or newer.
What type of vulnerability is CVE-2026-1606?
CVE-2026-1606 is classified as an improper control of generation of code, specifically related to code injection and input validation.
Who is affected by CVE-2026-1606?
CVE-2026-1606 affects users of GitLab CE and GitLab EE versions prior to 18.11.6, 19.0.3, and 19.1.1.
What can an attacker do with CVE-2026-1606?
An authenticated user could potentially conceal content within a Snippet due to improper input validation in CVE-2026-1606.