← Back to CVE List
CVE-2026-78252NVD
Vulnerability Summary
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.3 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an authenticated user could have induced a targeted user to perform unintended state-changing HTTP requests due to improper sanitization of user-controlled data in the Markdown JSON table renderer.
CVSS v3.1 Base Metrics — Score 8.2 (HIGH)
Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionRequired
ScopeChanged
ConfidentialityHigh
IntegrityHigh
AvailabilityLow
Affected & Patched Versions
- Gitlab Gitlab >= 15.3.0 and < 19.1.8
- Gitlab Gitlab >= 19.2.0 and < 19.2.6
- Gitlab Gitlab >= 19.3.0 and < 19.3.2
- Gitlab Gitlab 19.1.8
- Gitlab Gitlab 19.2.6
- Gitlab Gitlab 19.3.2