← Back to CVE List
CVE-2026-1090NVD
Vulnerability Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user, when the `markdown_placeholders` feature flag was enabled, to inject JavaScript in a browser due to improper sanitization of placeholder content in markdown processing.
CVSS v3.1 Base Metrics — Score 8.7 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityNone
Affected & Patched Versions
- Gitlab Gitlab >= 10.6.0 and < 18.7.6
- Gitlab Gitlab >= 18.8.0 and < 18.8.6
- Gitlab Gitlab >= 18.9.0 and < 18.9.2
- Gitlab Gitlab 18.7.6
- Gitlab Gitlab 18.8.6
- Gitlab Gitlab 18.9.2