CVE-2026-3254: Improper Restriction of Rendered UI Layers or Frames issue in Mermaid sandbox impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user to load unauthorized content into another user’s browser due to improper input validation in the Mermaid sandbox.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-3254?
CVE-2026-3254 is categorized as a moderate severity vulnerability due to potential unauthorized content loading in user browsers.
How do I fix CVE-2026-3254?
To remediate CVE-2026-3254, upgrade GitLab CE/EE to version 18.11.1 or later.
Which versions are affected by CVE-2026-3254?
CVE-2026-3254 affects all versions of GitLab CE and GitLab EE from 18.11 before 18.11.1.
What type of vulnerability is CVE-2026-3254?
CVE-2026-3254 is classified as an improper restriction of rendered UI layers or frames.
Who is impacted by CVE-2026-3254?
Authenticated users of GitLab CE and EE versions from 18.11 before 18.11.1 are at risk due to CVE-2026-3254.