CVE-2026-2973: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to execute arbitrary JavaScript in a user’s browser due to improper sanitization of entity-encoded content in Mermaid diagrams.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-2973?
CVE-2026-2973 has been classified as a significant security issue due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2026-2973?
To resolve CVE-2026-2973, upgrade GitLab to version 18.8.7, 18.9.3, or 18.10.1.
Which versions of GitLab are affected by CVE-2026-2973?
CVE-2026-2973 affects all GitLab CE/EE versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1.
Who can exploit CVE-2026-2973?
An authenticated user could potentially exploit CVE-2026-2973 to execute arbitrary JavaScript on affected systems.
What impact does CVE-2026-2973 have?
The impact of CVE-2026-2973 includes the risk of unauthorized data access and manipulation through JavaScript execution.