Vulnerability record · CVE-2022-1175 · published 4 April 2022
CVE-2022-1175: GitLab CE/EE stored XSS via HTML injection in notes
Gitlab · Gitlab
GitLab CE/EE fails to properly neutralize user input in notes, allowing HTML injection that results in cross-site scripting. The flaw affects versions 14.4 before 14.7.7, 14.8 before 14.8.5, and 14.9 before 14.9.2. Because notes are widely viewed by other users, a successful injection can run script in victims' sessions within the GitLab origin.
Description
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityThe CVSS score is medium (6.1) and there is no confirmed active exploitation, but the very high EPSS percentile and public exploit detail raise the practical risk for unpatched GitLab instances.
What it is
GitLab CE/EE fails to properly neutralize user input in notes, allowing HTML injection that results in cross-site scripting. The flaw affects versions 14.4 before 14.7.7, 14.8 before 14.8.5, and 14.9 before 14.9.2. Because notes are widely viewed by other users, a successful injection can run script in victims' sessions within the GitLab origin.
Impact
An attacker can execute arbitrary script in the browser of any user who views the crafted note, potentially stealing session tokens or performing actions as the victim. The CVSS scope change (S:C) reflects impact beyond the vulnerable component.
Attack surface
Reached over the network through the GitLab web interface by injecting HTML into a note; the CVSS vector indicates no privileges are required (PR:N) but a victim must interact with or view the malicious content (UI:R).
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.82003, 99.6th percentile), and public references include a Packet Storm advisory and a HackerOne report, indicating public technical detail exists, though the record does not confirm active exploitation.
What to do
- Upgrade GitLab CE/EE to 14.7.7, 14.8.5, 14.9.2 or later; these are the fixed versions named in the advisory.
- If immediate upgrade is not possible, restrict note creation and review permissions to trusted users and monitor for suspicious HTML content in notes.
- Enable GitLab's built-in content security controls and ensure output encoding/sanitization settings are current.
- Review GitLab release notes and the vendor CVE JSON for any additional hardening guidance tied to this issue.
Detection
- Search GitLab application logs and audit events for notes containing HTML tags or script-like payloads.
- Monitor for user reports of unexpected pop-ups, redirects, or script execution when viewing notes.
- Inspect web proxy or WAF logs for encoded script payloads submitted to GitLab note endpoints.
- Correlate GitLab access logs for anomalous session activity following note views by privileged users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html | Third Party AdvisoryVDB Entry |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/353370 | Broken Link |
| https://hackerone.com/reports/1481207 | Permissions RequiredThird Party Advisory |
| http://packetstormsecurity.com/files/166829/Gitlab-14.9-Cross-Site-Scripting.html | Third Party AdvisoryVDB Entry |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2022/CVE-2022-1175.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/353370 | Broken Link |
| https://hackerone.com/reports/1481207 | Permissions RequiredThird Party Advisory |
Track CVE-2022-1175 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-1175), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.