CVE-2026-10712Patch(gitlab / gitlab)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to improper path validation under certain conditions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 4 signals
  • General: 1 classified signal
  • Peaked 2d ago at 3 mentions (2026-06-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
gitlab

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-06-25: 3Mentions · 2026-06-26: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-06-25: 3Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 3Technical Details · 2026-06-26: 106-2506-2607-07
Signal classification2 categories
Patch
480.0%
General
120.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-253
Patch3
2026-06-261
Patch1
2026-07-071
General1
Full discourse5 posts
  • Rahmi Demir ⭐⭐⭐⭐⭐@rahmid3mir
    Patch

    🚨 #GüvenlikBülteni #SiberGüvenlik: GitLab EE Analytics Dashboard'da Kritik XSS Zafiyeti (CVE-2026-10086 / CVE-2026-10712 / CVE-2026-12053) Merhaba #Brolyz GitLab Enterprise Edition (EE) platformunun "Analytics" panosunda, kullanıcı girdilerinin yetersiz temizlenmesinden kaynaklanan yüksek riskli bir Siteler Arası Komut Dosyası Çalıştırma (Cross-Site Scripting - XSS) zafiyeti tespit edilmiştir. İlgili zafiyet T.C. Siber Güvenlik Başkanlığı (USOM) tarafından da TR-26-0447 kodlu bildirim ile Türkiye'deki kurumların dikkatine sunulmuştur. 📌 Ne Oluyor? Kimliği doğrulanmış ve Developer yetkisine sahip bir kullanıcı, Analytics paneline zararlı JavaScript kodu yerleştirebiliyor. Bu kodu görüntüleyen diğer kullanıcıların tarayıcılarında zararlı içerik otomatik olarak çalıştırılabiliyor. ⚠️ Riskler Neler? • Oturum bilgilerinin ele geçirilmesi • Kullanıcı yetkileriyle yetkisiz işlemler yapılması • Kaynak kod depolarına erişim sağlanması • CI/CD süreçlerinin ve geliştirme ortamlarının riske girmesi 🛡️ Alınması Gereken Önlemler 1️⃣ GitLab EE sunucularını 19.1.1, 19.0.3 veya 18.11.6 (veya daha yeni) sürümlere yükseltin. 2️⃣ 16.4–18.11.6, 19.0–19.0.3 ve 19.1–19.1.1 aralığındaki sürümlerin etkilenip etkilenmediğini kontrol edin. 3️⃣ Güncelleme tamamlanana kadar Analytics paneline yönelik olağan dışı istekleri ve Developer hesap aktivitelerini SIEM/WAF üzerinden izleyin. 4️⃣ Şüpheli oturum hareketleri ve beklenmeyen JavaScript çalıştırma girişimleri için güvenlik loglarını düzenli olarak inceleyin. 📊 Neden Önemli? GitLab, birçok kurumun yazılım geliştirme ve CI/CD süreçlerinin merkezinde yer alıyor. Böyle bir XSS zafiyeti, yalnızca kullanıcı hesaplarını değil, kaynak kod güvenliğini ve yazılım tedarik zincirini de doğrudan etkileyebilir. 🔚 Sonuç GitLab EE kullanan kurumların etkilenen sürümleri vakit kaybetmeden güncellemesi ve Analytics paneline yönelik şüpheli aktiviteleri yakından takip etmesi kritik önem taşıyor.

    Post summary

    The message is a patch advisory for GitLab EE XSS vulnerabilities (CVE‑2026‑10086/10712/12053), urging affected organizations to upgrade and monitor their Analytics panels.

    02020181
    540 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple high-severity vulnerabilities patched in #GitLab: CVE-2026-10086, CVE-2026-12053, & CVE-2026-10712 (Max CVSS: 8.7). Attackers can compromise user sessions & execute unauthorized actions via #XSS! #Patch #Patch #Patch https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-1-released/

    Post summary

    The post announces that multiple high‑severity GitLab CVEs have been patched (CVE‑2026‑10086, CVE‑2026‑12053, CVE‑2026‑10712, Max CVSS 8.7) and provides a link to the official patch release.

    01002657
    7.2K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-12053 ❗ CVE-2026-10712 ❗ CVE-2026-10086 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-14/ https://t.co/1j8MaxwVNX

    Post summary

    Three GitLab CVEs (CVE-2026-12053, CVE-2026-10712, CVE-2026-10086) are listed with a link for more information, but no technical or exploit details are provided.

    00000249
    6.7K followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-10712 - Stored #XSS in #GitLab @gitlab CE/EE. Unauthenticated #JS execution via improper path validation. #CVSS 8.0. Update to patched versions immediately. #CVE #git #infosec #cybersecurity #DevSecOps #devops #sysadmin More detailed FREE info: https://www.valtersit.com/cve/CVE-2026-10712/

    Post summary

    The text announces a stored XSS vulnerability in GitLab that allows unauthenticated JavaScript execution and urges users to update to patched versions immediately.

    0000059
    965 followersView on X
  • Xavier Rivera@XavierRiveraX
    Patch

    GitLab patched 13 vulnerabilities in CE/EE, including an unauthenticated XSS in the Web IDE workbench (CVE-2026-10712). An attacker with no GitLab account can execute JavaScript in any developer's browser session via a crafted asset request. Self-managed admins should update now; zero-authentication access to developer sessions exposes CI/CD secrets and source code.

    Post summary

    GitLab has released a patch for CVE-2026-10712, an unauthenticated XSS flaw in its Web IDE that could expose CI/CD secrets; administrators are advised to update immediately.

    0000065
    579 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab19.1.0--

Explore more