High severity7.3NVD Advisory· Published Jul 8, 2026· Updated Jul 9, 2026
CVE-2026-13320
CVE-2026-13320
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to improper sanitization of user-supplied input.
Affected products
27cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.7.0,<18.11.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.7.0,<18.11.7
- (no CPE)
- (no CPE)range: <18.11.7, <19.0.4, <19.1.2
- Range: <18.11.7, <19.0.4, <19.1.2
- osv-coords22 versionspkg:bitnami/gitlabpkg:apk/chainguard/gitlab-docker-machine-19.1pkg:apk/chainguard/gitlab-docker-machine-fips-19.1pkg:apk/chainguard/gitlab-rails-ce-18.11pkg:apk/chainguard/gitlab-rails-ce-assets-18.11pkg:apk/chainguard/gitlab-rails-ce-doc-18.11pkg:apk/chainguard/gitlab-runner-19.1pkg:apk/chainguard/gitlab-runner-fips-19.1pkg:apk/chainguard/gitlab-runner-helper-19.1pkg:apk/chainguard/gitlab-runner-helper-compat-19.1pkg:apk/chainguard/gitlab-runner-helper-compat-fips-19.1pkg:apk/chainguard/gitlab-runner-helper-fips-19.1pkg:apk/chainguard/gitlab-runner-helper-oci-entrypoint-19.1pkg:apk/chainguard/gitlab-runner-helper-oci-entrypoint-fips-19.1pkg:apk/chainguard/gitlab-runner-oci-entrypoint-19.1pkg:apk/chainguard/gitlab-runner-oci-entrypoint-fips-19.1pkg:apk/wolfi/gitlab-docker-machine-19.1pkg:apk/wolfi/gitlab-runner-19.1pkg:apk/wolfi/gitlab-runner-helper-19.1pkg:apk/wolfi/gitlab-runner-helper-compat-19.1pkg:apk/wolfi/gitlab-runner-helper-oci-entrypoint-19.1pkg:apk/wolfi/gitlab-runner-oci-entrypoint-19.1
>= 15.7.0, < 18.11.7+ 21 more
- (no CPE)range: >= 15.7.0, < 18.11.7
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 18.11.7-r0
- (no CPE)range: < 18.11.7-r0
- (no CPE)range: < 18.11.7-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
- (no CPE)range: < 19.1.2-r0
Patches
Vulnerability mechanics
References
2- docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-released/nvdVendor Advisory
- hackerone.com/reports/3816917nvdPermissions Required
News mentions
4- ⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and MoreThe Hacker News · Jul 13, 2026
- GitLab Patches Eight Security Vulnerabilities Across Community and Enterprise EditionsCyber Security News · Jul 9, 2026
- GitLab: Three Vulnerabilities Including Script Execution Fixed in July 8 Patch ReleaseVypr Intelligence · Jul 8, 2026
- GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7GitLab Security Releases · Jul 8, 2026