← Back to news

GitLab Patches Code Execution, Information Disclosure Vulnerabilities

SecurityWeek25/06/2026, 11:10
Read full article →

Summary

AI-Generated

Key Points:

  • GitLab has released security updates addressing 13 vulnerabilities, including three high-severity issues (CVE-2026-10086, CVE-2026-10712, CVE-2026-12053).
  • The vulnerabilities could allow authenticated users to execute arbitrary code or unauthenticated attackers to access sensitive information, potentially leading to data exfiltration and unauthorized access.
  • Users are strongly advised to upgrade to GitLab CE/EE versions 19.1.1, 19.0.3, or 18.11.6 to mitigate these risks.

Technical Details: CVE-2026-10086 is an XSS vulnerability that allows authenticated users to execute client-side code in other users' sessions, while CVE-2026-10712 enables unauthenticated attackers to run JavaScript in users' browsers. CVE-2026-12053 involves insufficient output filtering that could expose sensitive project information.

MITRE ATT&CK Techniques: None mentioned

IOCs Mentioned: None mentioned

Join the discussion — sign up to comment, upvote, and save articles.

Discussion

or to comment
Loading...

Loading comments...

Join 5,000+ security professionals

Get access to curated threat intel, upvote articles, join discussions, and build your karma in the SOC community.