What is CVE-2026-3093?
CVE-2026-3093 is a DOM-based XSS vulnerability discovered in GitLab CE/EE, allowing arbitrary JavaScript execution in a victim's browser via a crafted URL due to improper sanitization. The issue impacts versions from 14.0 and has been patched in GitLab versions 19.0.5, 19.1.3, and 19.2.1, requiring an immediate update.
Azərbaycanca: CVE-2026-3093 GitLab CE/EE platformasında aşkarlanmış DOM-based XSS zəifliyidir. Bu boşluq xüsusi hazırlanmış URL vasitəsilə istifadəçinin brauzerində JavaScript kodunun icrasına imkan verir. GitLab tərəfindən təqdim olunan 19.0.5, 19.1.3 və 19.2.1 versiyalarına təcili yenilənmə tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GitLab
FAQ2
What is CVE-2026-3093?
CVE-2026-3093 is a DOM-based XSS vulnerability discovered in GitLab CE/EE, allowing arbitrary JavaScript execution in a victim's browser via a crafted URL due to improper sanitization.
Which versions are patched against CVE-2026-3093?
The issue has been patched in GitLab versions 19.0.5, 19.1.3, and 19.2.1, requiring an immediate update.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.