GitLab product security update advisory

GitLab product security update advisory

Summary. Cross-site request forgery in the GraphQL API (CVE-2026-4922), cross-site scripting in Storybook (CVE-2026-5262), and poor path equivalence handling in Web IDE assets (CVE-2026-5816) have been announced in GitLab CE/EE. affected products span multiple 16.x-18.x version bands, with specific version ranges for each vulnerability. the vulnerabilities are resolved through updates