CVE-2026-5816 is a cross-site scripting vulnerability affecting GitLab Community Edition and Enterprise Edition versions 18.10 before 18.10.4 and 18.11 before 18.11.1. The flaw stems from improper path validation that allows unauthenticated attackers to inject and execute arbitrary JavaScript code within a victim's browser session under specific conditions. This vulnerability requires user interaction to trigger but can result in complete compromise of session confidentiality and integrity. The vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 8.0, reflecting its network-accessible attack vector and requirement for user interaction. The attack has high complexity and does not require authentication, but successful exploitation depends on tricking users into performing specific actions. The potential impact includes high confidentiality and integrity violations, though availability is not affected. There is no evidence of active exploitation in the wild, as the vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and remains inactive on threat tracking lists. The EPSS score of 0.00012 indicates extremely low probability of exploitation in real-world scenarios compared to other published CVEs. Organizations should prioritize patching to the fixed versions (18.10.4 or 18.11.1 and later) as part of routine security maintenance but need not treat this as an emergency incident response priority.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.10, < 18.10.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.11, < 18.11.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.10.0, < 18.10.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.10.0, < 18.10.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
18.11.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:18.11.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.