www.securityweek.com 6/25/2026, 11:20:38 AM · external

GitLab fixes critical XSS flaws in Analytics dashboard

GitLab fixes critical XSS flaws in Analytics dashboard
Developing story vulnerability 2 articles tracked
GitLab patches multiple critical vulnerabilities including XSS flaws
CyberSIXT Evidence Panel
Primary Source docs.gitlab.com
CISA KEV Not in KEV
Patch Patch Available

GITLAB released security updates for Community Edition (CE) and Enterprise Edition (EE) addressing 13 vulnerabilities, including three high-severity issues. The most critical, CVE-2026-10086, is an XSS flaw in the Analytics dashboard allowing authenticated users to execute code in others' sessions. Another severe flaw, CVE-2026-10712, allows unauthenticated attackers to run JavaScript in users' browsers. Additionally, CVE-2026-12053 could expose sensitive project information.

Other medium-severity vulnerabilities include authorization bypass and improper input validation. Users are urged to update to versions 19.1.1, 19.0.3, or 18.11.6 immediately to mitigate these risks.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline