CVE-2025-6016
CVE-2026-4922 is a cross-site request forgery vulnerability affecting the GraphQL API. Insufficient CSRF protection in GitLab GraphQL API allows unauthenticated users to execute GraphQL mutations on behalf of authenticated users. An attacker can craft malicious requests that, when clicked by an authenticated GitLab user, execute GraphQL mutations without the user's knowledge or consent. This could result in unauthorised modification of data and configurations within GitLab, including potential changes to project settings, user permissions, issue management, and other critical GitLab functionality. CVE-2026-5816 is an improper resolution of path equivalence flaw affecting Web IDE assets. An unauthenticated user could exploit it to execute arbitrary JavaScript in a user’s browser session. This could lead to session hijacking, credential theft, unauthorised actions performed on behalf of the user, and potential access to sensitive data. CVE-2026-5262 is a cross-site scripting vulnerability affecting Storybook. Under certain conditions, an unauthenticated attacker could exploit this vulnerability to gain unauthorised access to sensitive tokens stored in the Storybook development environment. This could lead to the compromise of authentication credentials, allowing attackers to authenticate as legitimate users and perform actions on the GitLab instance.
EPSS 0.03% · 9.7th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| GitLab | GitLab Community Edition | |
| GitLab | GitLab Enterprise Edition |
Timeline
- Aug 7, 2025 CVE Published
- Apr 22, 2026 PoC Published
- Apr 23, 2026 Security Advisory
- May 18, 2026 EPSS Score
- May 19, 2026 EPSS Score
- May 20, 2026 EPSS Score
- May 21, 2026 EPSS Score
- May 22, 2026 EPSS Score
- May 23, 2026 EPSS Score
- May 24, 2026 EPSS Score
- May 25, 2026 EPSS Score
- May 26, 2026 EPSS Score
References
- https://ccb.belgium.be/advisories/warning-11-new-vulnerabilities-gitlab-ce-and-ee-editions-patch-immediately advisory
- https://docs.gitlab.com/releases/patches/patch-release-gitlab-18-11-1-released/ vendor
- https://feedly.com/cve/CVE-2026-4922 technical
- https://feedly.com/cve/CVE-2026-5816 technical
- https://feedly.com/cve/CVE-2026-5262 technical