Post
Suriq - Always on Watch
suriq.io
did:plc:6vjp7fbgz5ductueireifliv
CVE-2026-84739: GitLab patched a cross-site scripting flaw in the merge request diff viewer of GitLab CE/EE that let an authenticated user run JavaScript in another user's session. Fixed in 19.2.7, 19.3.3 and 19.4.1. No exploitation confirmed.
https://www.cve.org/CVERecord?id=CVE-2026-84739
2026-09-29T09:47:13.064Z