GitLab CE/EE Input Validation Vulnerability in Mermaid Sandbox Allowing Cross-User Content Injection

Vulnerability

A vulnerability exists in GitLab CE/EE versions 18.11 prior to 18.11.1, where improper input validation in the Mermaid sandbox could have allowed an authenticated user to inject unauthorized content into another user's browser under certain conditions.

Impact

Exploitation of this vulnerability could lead to cross-user content injection, allowing an authenticated user to load unauthorized content into another user's browser.

Added: Apr 22, 2026, 5:23 PM
Updated: Apr 22, 2026, 5:23 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.2
exploitability
5.0
remediation
7.7
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.