CVE-2026-2973
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to execute arbitrary JavaScript in a user's browser due to improper sanitization of entity-encoded content in Mermaid diagrams.
Summary dbcve.org
GitLab contains a stored XSS vulnerability where authenticated users can inject arbitrary JavaScript through Mermaid diagrams due to improper sanitization of entity-encoded content. When other users view the affected Mermaid diagram, the malicious payload executes in their browsers.
Mitigation
Upgrade to GitLab versions 18.8.7, 18.9.3, 18.10.1 or later. If immediate patching is not possible, restrict or disable Mermaid diagram rendering until the patch can be applied.