GitLab released 19.1.2, 19.0.4, and 18.11.7 to fix eight security vulnerabilities in GitLab Community Edition and Enterprise Edition, including two high-severity script-injection issues. One of the disclosed flaws, CVE-2026-6896, is a CWE-79 cross-site scripting vulnerability in GitLab EE that could let an authenticated user with Developer privileges execute arbitrary script in another user’s browser under certain conditions. The issue affects releases from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2.
The patch set also addresses a medium-severity credential exposure issue and several authorization and access-control weaknesses. GitLab said GitLab.com was already patched and GitLab Dedicated customers do not need to take action, but urged operators of self-managed instances on affected versions to upgrade immediately. The release includes database migrations that may cause downtime on single-node deployments, while multi-node environments can avoid interruption by following GitLab’s zero-downtime upgrade procedures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
GitLab's July 8, 2026 security release was described as fixing eight vulnerabilities across Community Edition and Enterprise Edition, including CVE-2026-13320, an HTML injection flaw, plus issues involving repository mirroring credential exposure, private project metadata leakage, project existence inference, authorization weaknesses, and Git reference ambiguity. GitLab also said GitLab Dedicated customers were unaffected and that fuller disclosures would follow after 90 days.
CVE-2026-6896 was disclosed as an improper neutralization of input during web page generation issue in GitLab EE that could let an authenticated user with developer-role permissions execute arbitrary scripts in another user's browser under certain conditions. The issue affects releases from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2, and GitLab remediated it in the fixed releases.
On 2026-07-08, GitLab released versions 19.1.2, 19.0.4, and 18.11.7 for Community Edition and Enterprise Edition to fix multiple security vulnerabilities and bug fixes. GitLab said GitLab.com was already patched and advised self-managed customers to upgrade immediately.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecvefeed.io
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.