4.3

CVE-2026-1606

Improper Control of Generation of Code ('Code Injection') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab Version >= 14.8.0 < 18.11.6
Gitlab ≫ GitLab Version >= 19.0.0 < 19.0.3
Gitlab ≫ GitLab Version 19.1.0
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.22% 0.131
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
cve@gitlab.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/
Vendor Advisory
Release Notes
https://gitlab.com/gitlab-org/gitlab/-/work_items/588128
Broken Link
https://hackerone.com/reports/3527473
Permissions Required