CVE-2026-84739 GitLab CE/EE 跨站脚本漏洞
影响认证用户可在他人的浏览器会话中执行任意JavaScript
GitLab CE/EE 的合并请求差异查看器对路径组件清理不当,存在存储型跨站脚本风险。攻击者通过构造恶意路径内容,可在其他用户浏览该差异页面时执行任意 JavaScript。官方已发布修复版本。
影响范围
GitLab CE/EE 13.11 起至 19.2.7 之前、19.3 至 19.3.3 之前、19.4 至 19.4.1 之前的版本。
漏洞详情
漏洞类型为跨站脚本(XSS),成因是合并请求差异查看器未正确清理路径组件中的特殊字符。已认证用户可提交包含恶意路径的合并请求内容,当其他用户查看该差异时,脚本会在其浏览器上下文中执行。
利用条件与风险
利用需攻击者拥有有效账号并能诱导受害者查看恶意合并请求差异页面,可导致会话劫持或敏感信息窃取,实战风险较高。
修复建议
升级至 GitLab 19.2.7、19.3.3 或 19.4.1 及以上版本;临时缓解措施暂无公开信息。
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.11 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary JavaScript in the context of another user’s browser session due to improper sanitization of path components in the merge request diff viewer.