August 3, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-6335NVD

Vulnerability Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.3 that under certain conditions could have allowed an authenticated user to execute arbitrary code in another user's browser session due to improper sanitization.
Severity Level
MEDIUM(5.4)
Published Date
May 14, 2026
Last Modified
May 15, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.03%Probability
Root Weakness (CWE)
The software does not neutralize user-controllable input before it is placed in output that is used as a web page.
CVSS v3.1 Base Metrics
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
ScopeChanged
ConfidentialityLow
IntegrityLow
AvailabilityNone