CVE-2026-7377Disclosure(gitlab / gitlab)

LOWCVSS 5.4 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that, in customizable analytics dashboards, could have allowed an authenticated user to execute arbitrary JavaScript in the context of other users' browsers due to improper input sanitization.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-14); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-14: 1Mentions · 2026-05-27: 1Technical Details · 2026-05-14: 105-1405-27
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-271
General1
Full discourse2 posts
  • ZoomEye@zoomeye_team
    Disclosure

    🚨 CVE-2026-7377: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab Stored XSS in Custom Analytics Dashboards An authenticated attacker could inject malicious JavaScript into customizable analytics dashboards via unsanitized user input, leading to arbitrary code execution in the browsers of other users viewing those dashboards. Full Vulnerability Details & Analysis at DarkEye: 🔗 https://darkeye.org/vuln/cve/CVE-2026-7377 🔍 Identify Targets via ZoomEye: Filter: vul.cve="CVE-2026-7377" Search Dork: app="Gitlab" Exposure: 1.2m+ instances identified globally. ZoomEye Search Link: 👉 https://www.zoomeye.ai/searchResult?q=YXBwPSJHaXRsYWIi&utm_source=twitter&utm_medium=social&utm_campaign=cve_ops_20260514 #XSS #GitLab #StoredXSS #DashboardVuln #CVE20267377 #DarkEye

    Post summary

    The tweet reports a new stored XSS vulnerability (CVE‑2026‑7377) in GitLab's custom analytics dashboards, provides technical details, global exposure figures via ZoomEye, and links to a full analysis, but offers no PoC, exploit code, patch, or evidence of active exploitation.

    06023114.4K
    12.5K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-7481 ❗ CVE-2026-7377 ❗ CVE-2026-6073 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-11/ https://t.co/mhOPRUdFVq

    Post summary

    A brief notice listing three GitLab CVEs with links for additional information.

    01011138
    6.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---

Explore more