High severity8.7NVD Advisory· Published Jan 18, 2022· Updated Jun 17, 2026
CVE-2021-39946
CVE-2021-39946
Description
Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2
14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2+ 1 more
- (no CPE)range: 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2
- (no CPE)range: >=14.3, <14.3.6
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39946.jsonnvdVendor Advisory
- gitlab.com/gitlab-org/gitlab/-/issues/345657nvdBroken LinkVendor Advisory
- hackerone.com/reports/1398305nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.