VYPR
Vypr IntelligenceAI-generatedSep 29, 2026· 5 CVEs

GitLab Patches Four Vulnerabilities, Including High-Severity JS Execution Flaw

GitLab Inc. patched four vulnerabilities on September 29, 2026, including a high-severity flaw allowing arbitrary JavaScript execution and issues enabling unauthorized data access.

Key findings

  • Four GitLab vulnerabilities disclosed on September 29, 2026, range from low to high severity.
  • High-severity CVE-2026-84739 allows arbitrary JavaScript execution via CI/CD configurations.
  • Medium-severity CVE-2026-8937 enables reading private issue details without authorization.
  • Low-severity CVE-2026-4523 permits unauthenticated access to sensitive CI/CD job variables.
  • All vulnerabilities are fixed in GitLab versions 19.2.7, 19.3.3, and 19.4.1.

On September 29, 2026, GitLab Inc. disclosed four vulnerabilities affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The vulnerabilities, addressed in patch releases 19.2.7, 19.3.3, and 19.4.1, span a range of severity levels, from low to high, and impact different aspects of the platform, including issue tracking, CI/CD pipelines, and security policy management.

One of the most critical issues, CVE-2026-84739, is a high-severity vulnerability that could allow an authenticated user to execute arbitrary JavaScript in the context of another user's browser session. This flaw stems from improper sanitization of user input within the CI/CD features. Related security news indicated that this vulnerability, along with another (CVE-2026-89078, not in this batch), could be exploited through malicious CI/CD regular expressions, potentially leading to code execution. The patched versions are 19.2.7, 19.3.3, and 19.4.1.

Another notable vulnerability, CVE-2026-8937, is a medium-severity issue that could permit an authenticated user to read private child issue contents, including titles and descriptions, from projects they would not normally have access to. This vulnerability affects all versions prior to 19.2.7, 19.3.3, and 19.4.1.

A separate medium-severity vulnerability, CVE-2026-10518, impacts GitLab EE. It could allow an authenticated user with guest-level permissions to access private security policy content they are not authorized to view. This issue is also fixed in the aforementioned patch releases.

Finally, a low-severity vulnerability, CVE-2026-4523, could enable an unauthenticated user to read sensitive variable values from CI/CD job traces due to improper authorization enforcement. This flaw affects versions prior to 19.2.7, 19.3.3, and 19.4.1.

GitLab addressed these vulnerabilities in coordinated patch releases on September 23, 2026, with versions 19.4.1, 19.3.3, and 19.2.7. Administrators of self-managed GitLab instances are strongly urged to upgrade to these patched versions immediately. GitLab.com is already running the fixed versions, and GitLab Dedicated customers do not require any action.

The coordinated disclosure of these vulnerabilities highlights the importance of timely patching for GitLab instances. Users should ensure they are running the latest secure versions to protect against potential data leakage and unauthorized access. The range of affected components underscores the need for a comprehensive security approach when managing GitLab deployments.

AI-written article. Grounded in 5 CVE records listed below.