What is CVE-2026-15217?
This vulnerability exists in GitLab CE/EE and could allow cross-site scripting (XSS) under certain conditions due to improper neutralization of user-controlled values in table cell content. Organizations using affected versions between 18.2 and 19.0.6, 19.1.4, or 19.2.2 should immediately upgrade to the latest patched releases.
Azərbaycanca: Bu boşluq GitLab CE/EE platformasında aşkar edilmişdir və müəyyən şərtlər altında istifadəçi tərəfindən idarə olunan dəyərlərin düzgün təmizlənməməsi səbəbindən cross-site scripting (XSS) hücumuna yol aça bilər. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal 19.0.6, 19.1.4, 19.2.2 və ya daha yuxarı versiyalara yeniləmə aparmalıdırlar.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GitLab
FAQ2
What platform does CVE-2026-15217 affect, and what security risk does it pose?
This vulnerability exists in GitLab CE/EE and could allow cross-site scripting (XSS) under certain conditions due to improper neutralization of user-controlled values.
Which versions should be upgraded to in order to mitigate CVE-2026-15217?
Organizations using affected versions should immediately upgrade to 19.0.6, 19.1.4, 19.2.2 or later patched releases.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.