CVE-2026-10087: GitLab EE Stored XSS via Developer Role
ID: f0b66e3c-56da-590b-8638-f66ec3feab9a
STIX ID: report--f0b66e3c-56da-590b-8638-f66ec3feab9a
Feed Name: CosmicBytez Labs
## Executive Summary CVE-2026-10087 is a stored XSS in GitLab Enterprise Edition (CVSS 8.7) that enables authenticated Developer-role users to inject JavaScript executed in other users' sessions — potentially allowing session theft, API misuse, privilege escalation, and CI/CD supply-chain compromise; affected self-managed EE versions are 17.1–18.10.7, 18.11.0–18.11.4, and 19.0.0–19.0.1 and are fixed in 18.10.8, 18.11.5, and 19.0.2, with urgent upgrades and access restrictions recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
