Medium severity4.7NVD Advisory· Published Sep 16, 2026
CVE-2026-19619
CVE-2026-19619
Description
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in the context of a targeted user's session due to improper sanitization of pasted HTML content in the Content Editor.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
- Range: from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2
Patches
Vulnerability mechanics
References
2News mentions
1- GitLab Critical Patch Release: 19.3.2, 19.2.6, 19.1.8GitLab Security Releases · Sep 10, 2026