CVE-2026-5816: Improper Resolution of Path Equivalence issue in Web IDE asset impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.4 and 18.11 before 18.11.1 that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to execute arbitrary JavaScript in a user’s browser session due to improper path validation under certain conditions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-5816?
CVE-2026-5816 has a severity rating of medium due to the potential for unauthenticated users to execute arbitrary JavaScript.
How do I fix CVE-2026-5816?
To fix CVE-2026-5816, upgrade GitLab to version 18.10.4 or 18.11.1 or later.
What versions are affected by CVE-2026-5816?
CVE-2026-5816 affects GitLab CE/EE versions from 18.10 to 18.10.4 and from 18.11 to 18.11.1.
What impact does CVE-2026-5816 have on my system?
CVE-2026-5816 allows unauthenticated users to execute arbitrary JavaScript in a user's browser, potentially leading to data exposure or session hijacking.
Is CVE-2026-5816 related to any specific GitLab features?
CVE-2026-5816 is related to the Web IDE asset management features in GitLab.