CVE-2026-5262: Cross-site Scripting issue in Storybook impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.1.0 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed an unauthenticated user to access tokens in the Storybook development environment due to improper input validation.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-5262?
CVE-2026-5262 is classified as a moderate severity cross-site scripting vulnerability.
How do I fix CVE-2026-5262?
To remediate CVE-2026-5262, upgrade to GitLab versions 18.9.6, 18.10.4, or 18.11.1.
Which versions of GitLab are affected by CVE-2026-5262?
CVE-2026-5262 affects GitLab versions from 16.1.0 to before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1.
Can CVE-2026-5262 be exploited by authenticated users?
CVE-2026-5262 can be exploited by unauthenticated users under certain conditions.
What type of vulnerability is CVE-2026-5262?
CVE-2026-5262 is identified as a cross-site scripting issue in Storybook that targets GitLab CE/EE.