MEDIUM

CVE-2026-2973

Gitlab GitLab 2026-03-25 CVSS v3.1
CVSS
5.4

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.

Summary dbcve.org

GitLab contains a stored XSS vulnerability where authenticated users can inject arbitrary JavaScript through Mermaid diagrams due to improper sanitization of entity-encoded content. When other users view the affected Mermaid diagram, the malicious payload executes in their browsers.

Mitigation

Upgrade to GitLab versions 18.8.7, 18.9.3, 18.10.1 or later. If immediate patching is not possible, restrict or disable Mermaid diagram rendering until the patch can be applied.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.17%
Probability of exploitation in next 30 days
7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE