CVE-2026-84739

medium

Description

The vulnerability exists due to improper sanitization of path components in the merge request diff viewer, allowing an authenticated user to execute arbitrary JavaScript in the context of another user's session.

Details

Source: Mitre, NVD

Published: 2026-09-24

Risk Information

CVSS v2

Base Score: 4.9

Vector: CVSS2#AV:N/AC:M/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Severity: Medium