Vulnerability record · CVE-2021-39906 · published 5 November 2021
CVE-2021-39906: GitLab ipynb file validation flaw enables stored XSS
Gitlab · Gitlab
GitLab CE/EE 13.5 and above fails to properly validate ipynb (Jupyter notebook) files, allowing injected JavaScript to run in a victim's browser. Because the payload is stored in a repository artifact, any user who views the rendered notebook can be targeted, making it a persistent cross-site scripting issue in a widely deployed DevOps platform.
Description
Improper validation of ipynb files in GitLab CE/EE version 13.5 and above allows an attacker to execute arbitrary JavaScript code on the victim's behalf.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityHigh EPSS (0.607, 99th percentile) and a persistent XSS in a widely used platform raise real risk despite the medium CVSS score and no confirmed in-the-wild exploitation.
What it is
GitLab CE/EE 13.5 and above fails to properly validate ipynb (Jupyter notebook) files, allowing injected JavaScript to run in a victim's browser. Because the payload is stored in a repository artifact, any user who views the rendered notebook can be targeted, making it a persistent cross-site scripting issue in a widely deployed DevOps platform.
Impact
An attacker can execute arbitrary JavaScript in the context of a victim's GitLab session, potentially stealing session tokens, performing actions as the victim, or exfiltrating data the victim can access. The CVSS scope change (S:C) reflects that impact can extend beyond the vulnerable component.
Attack surface
Reached over the network by rendering a crafted ipynb file in GitLab; the vector shows no privileges required (PR:N) but user interaction is required (UI:R) for the victim to view the malicious notebook. No authentication is needed by the attacker to deliver the payload, though the HackerOne reference is tagged Permissions Required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware usage is documented in the record. EPSS is high at 0.607 (99th percentile), indicating elevated likelihood of exploitation activity, but the record does not confirm in-the-wild exploitation.
What to do
- Upgrade GitLab CE/EE to a version that includes the fix for CVE-2021-39906; consult the vendor advisory for the exact patched release.
- If immediate upgrade is not possible, restrict or disable rendering of ipynb files and limit who can upload them.
- Apply a strict Content Security Policy to reduce the impact of injected JavaScript in rendered content.
- Review repository contents for suspicious ipynb files and remove any untrusted notebooks.
- Educate users not to open ipynb files from untrusted sources until patched.
Detection
- Search GitLab logs and repository history for ipynb files containing script tags or JavaScript event handlers.
- Monitor for anomalous outbound requests or session activity originating from users viewing notebook files.
- Alert on uploads of ipynb files by untrusted or external contributors.
- Review web proxy or browser telemetry for JavaScript execution patterns tied to GitLab notebook rendering.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39906.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/341566 | Broken Link |
| https://hackerone.com/reports/1347600 | Permissions RequiredThird Party Advisory |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-39906.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/341566 | Broken Link |
| https://hackerone.com/reports/1347600 | Permissions RequiredThird Party Advisory |
Track CVE-2021-39906 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39906), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.