← Vulnerability feed

Vulnerability record · CVE-2022-1175 · published 4 April 2022

CVE-2022-1175: GitLab CE/EE stored XSS via HTML injection in notes

Gitlab · Gitlab

GitLab CE/EE fails to properly neutralize user input in notes, allowing HTML injection that results in cross-site scripting. The flaw affects versions 14.4 before 14.7.7, 14.8 before 14.8.5, and 14.9 before 14.9.2. Because notes are widely viewed by other users, a successful injection can run script in victims' sessions within the GitLab origin.

6.1 CVSS 3.1 Medium EPSS 82% · top 0.4% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versions starting from 14.9 before 14.9.2 allowed an attacker to exploit XSS by injecting HTML in notes.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityThe CVSS score is medium (6.1) and there is no confirmed active exploitation, but the very high EPSS percentile and public exploit detail raise the practical risk for unpatched GitLab instances.

What it is

GitLab CE/EE fails to properly neutralize user input in notes, allowing HTML injection that results in cross-site scripting. The flaw affects versions 14.4 before 14.7.7, 14.8 before 14.8.5, and 14.9 before 14.9.2. Because notes are widely viewed by other users, a successful injection can run script in victims' sessions within the GitLab origin.

Impact

An attacker can execute arbitrary script in the browser of any user who views the crafted note, potentially stealing session tokens or performing actions as the victim. The CVSS scope change (S:C) reflects impact beyond the vulnerable component.

Attack surface

Reached over the network through the GitLab web interface by injecting HTML into a note; the CVSS vector indicates no privileges are required (PR:N) but a victim must interact with or view the malicious content (UI:R).

Exploitation

Not listed in CISA KEV and no ransomware associations are documented. EPSS is very high (0.82003, 99.6th percentile), and public references include a Packet Storm advisory and a HackerOne report, indicating public technical detail exists, though the record does not confirm active exploitation.

What to do

  • Upgrade GitLab CE/EE to 14.7.7, 14.8.5, 14.9.2 or later; these are the fixed versions named in the advisory.
  • If immediate upgrade is not possible, restrict note creation and review permissions to trusted users and monitor for suspicious HTML content in notes.
  • Enable GitLab's built-in content security controls and ensure output encoding/sanitization settings are current.
  • Review GitLab release notes and the vendor CVE JSON for any additional hardening guidance tied to this issue.

Detection

  • Search GitLab application logs and audit events for notes containing HTML tags or script-like payloads.
  • Monitor for user reports of unexpected pop-ups, redirects, or script execution when viewing notes.
  • Inspect web proxy or WAF logs for encoded script payloads submitted to GitLab note endpoints.
  • Correlate GitLab access logs for anomalous session activity following note views by privileged users.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-1175 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-85706GitLab CE/EE repository commits API path traversal allows unauthenticated file readGitLab CE/EE contains improper path confinement and missing authentication enforcement in the repository commits API, allowing an unauthenticated use…KEVEPSS 91%analysed10.0CVE-2021-22205GitLab CE/EE image parser flaw allows unauthenticated remote code executionGitLab CE/EE failed to properly validate image files passed to a file parser, allowing code injection that leads to remote command execution. The fla…KEVEPSS 100%analysed9.8CVE-2023-7028GitLab CE/EE password reset sent to unverified email, enabling account takeoverGitLab CE/EE versions from 16.1 through 16.7 before their fixed releases could deliver account password reset emails to an unverified email address. …KEVEPSS 95%analysed9.8CVE-2021-22175GitLab unauthenticated SSRF via internal webhook requestsGitLab is vulnerable to server-side request forgery when requests to the internal network for webhooks are enabled. The flaw affects all versions sta…KEVEPSS 53%analysed7.5CVE-2021-39935GitLab CI Lint API server-side request forgeryGitLab CE/EE contains a server-side request forgery flaw in the CI Lint API affecting versions from 10.5 before 14.3.6, 14.4 before 14.4.4, and 14.5 …KEVEPSS 36%analysed10.0CVE-2020-13300Gitlab incorrect authorization vulnerabilityGitLab CE/EE version 13.3 prior to 13.3.4 was vulnerable to an OAuth authorization scope change without user consent in the middle of the authorizati…EPSS 1.3%10.0CVE-2019-9174Gitlab server-side request forgery (ssrf) vulnerabilityAn issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows SSRF.EPSS 2.0%10.0CVE-2018-18843Gitlab server-side request forgery (ssrf) vulnerabilityThe Kubernetes integration in GitLab Enterprise Edition 11.x before 11.2.8, 11.3.x before 11.3.9, and 11.4.x before 11.4.4 has SSRF.EPSS 1.6%

Source: NIST National Vulnerability Database (record CVE-2022-1175), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.