Vulnerability record · CVE-2021-22238 · published 20 August 2021
CVE-2021-22238: GitLab stored XSS via issue design feature
Gitlab · Gitlab
GitLab versions starting with 13.3 are vulnerable to stored cross-site scripting through the design feature in issues. An attacker with a low-privileged account can inject script that executes in the browser of another user who views the affected design content. Because the injected payload persists, it can reach users beyond the original poster.
Description
An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityStored XSS in a widely deployed collaboration platform with a very high EPSS score warrants prompt patching despite the medium CVSS rating.
What it is
GitLab versions starting with 13.3 are vulnerable to stored cross-site scripting through the design feature in issues. An attacker with a low-privileged account can inject script that executes in the browser of another user who views the affected design content. Because the injected payload persists, it can reach users beyond the original poster.
Impact
An attacker can run arbitrary script in a victim's GitLab session, potentially stealing session tokens or acting as the victim within the application. The CVSS scope change indicates impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the issue design upload/view functionality; the attacker needs a low-privileged authenticated account, and a victim must view the crafted design, so user interaction is required.
Exploitation
Not listed in CISA KEV and no public exploit tag appears in the references, but EPSS is very high at 0.71787 (99.4th percentile), suggesting elevated likelihood of attempted exploitation.
What to do
- Upgrade GitLab to a release that includes the fix for CVE-2021-22238; patch first.
- Restrict who can create or edit issue designs to trusted roles until patched.
- Enforce a strict Content Security Policy to reduce script execution from injected content.
- Review and sanitize user-supplied design content and monitor for suspicious uploads.
Detection
- Search GitLab logs for design uploads or edits containing script tags, event handlers, or javascript: URIs.
- Monitor for anomalous requests to issue design endpoints from low-privileged accounts.
- Review application and proxy logs for reflected or stored XSS payload patterns in design-related parameters.
- Alert on unexpected session activity or token use following design views.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/332420 | Broken Link |
| https://hackerone.com/reports/1212067 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22238.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/332420 | Broken Link |
| https://hackerone.com/reports/1212067 | Permissions RequiredThird Party Advisory |
Track CVE-2021-22238 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-22238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.