CVE-2026-0752 | GitLab Community Edition/Enterprise Edition up to 18.7.4/18.8.4/18.9.0 Mermaid Sandbox UI cross site scripting (Issue 585371 / Nessus ID 300183)
A vulnerability has been found in GitLab Community Edition and Enterprise Edition up to 18.7.4/18.8.4/18.9.0 and classified as problematic. This vulnerability affects unknown code of the component Mermaid Sandbox UI. Performing a manipulation results in cross site scripting.
This vulnerability is cataloged as CVE-2026-0752. It is possible to initiate the attack remotely. There is no exploit available.
The affected component should be upgraded.