logo

GitLab Fixes Flaws That Could Allow Attackers to Hijack User Sessions

ID: e752e22b-ee2f-5d2c-b365-6ab0bf3195f8

STIX ID: report--e752e22b-ee2f-5d2c-b365-6ab0bf3195f8

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-04-23

Date Updated: 2026-04-23

Author: Divya

...
...

GitLab released emergency security patches (18.11.1, 18.10.4, 18.9.6) addressing 11 vulnerabilities across Community and Enterprise editions, including three high-severity flaws (CSRF in the GraphQL API, a Web IDE path validation issue enabling arbitrary JavaScript execution, and an XSS in Storybook) that could lead to session hijacking and token exposure; self-managed installations are strongly urged to upgrade immediately while GitLab.com has already been updated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.