PT-2026-34522 · Gitlab · Gitlab Ce/Ee

Published

2026-04-22

·

Updated

2026-04-22

·

CVE-2026-3254

CVSS v3.1

3.5

Low

AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.11 through 18.11.0
Description Improper input validation in the Mermaid sandbox could allow an authenticated user to load unauthorized content into another user's browser.
Recommendations Update to version 18.11.1.

Exploit

Fix

Clickjacking

Weakness Enumeration

Related Identifiers

CVE-2026-3254

Affected Products

Gitlab Ce/Ee