Vulnerability record · CVE-2023-0050 · published 9 March 2023
CVE-2023-0050: GitLab Kroki diagram stored XSS enables actions as victims
Gitlab · Gitlab
GitLab fails to properly sanitize specially crafted Kroki diagrams, allowing stored cross-site scripting. The flaw affects all versions from 13.7 before 15.7.8, from 15.8 before 15.8.4, and from 15.9 before 15.9.2. Because the payload is stored, it can execute in the browser of any user who views the affected diagram.
Description
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.4, all versions starting from 15.9 before 15.9.2. A specially crafted Kroki diagram could lead to a stored XSS on the client side which allows attackers to perform arbitrary actions on behalf of victims.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
high priorityStored XSS in an authenticated collaboration platform with a very high EPSS score and scope change can lead to account compromise, though it requires low privileges and user interaction.
What it is
GitLab fails to properly sanitize specially crafted Kroki diagrams, allowing stored cross-site scripting. The flaw affects all versions from 13.7 before 15.7.8, from 15.8 before 15.8.4, and from 15.9 before 15.9.2. Because the payload is stored, it can execute in the browser of any user who views the affected diagram.
Impact
An attacker can run arbitrary script in a victim's authenticated GitLab session, performing actions on the victim's behalf. The CVSS scope change (S:C) reflects that the impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through a crafted Kroki diagram rendered in GitLab; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning the victim must view the malicious diagram.
Exploitation
Not listed in CISA KEV and no public exploit reference is tagged; EPSS is very high at 0.9242 (99.8th percentile), indicating elevated predicted exploitation activity, though the record does not confirm active exploitation.
What to do
- Upgrade GitLab to 15.7.8, 15.8.4, or 15.9.2 (or later) as applicable to your release line.
- If immediate patching is not possible, restrict or disable Kroki diagram rendering until the upgrade is complete.
- Limit who can create or edit content containing diagrams to reduce the pool of users who can plant a stored payload.
- Review and remove any existing Kroki diagrams from untrusted contributors as part of remediation.
Detection
- Search GitLab content and database records for Kroki diagram blocks containing script tags or unusual HTML/JavaScript payloads.
- Monitor GitLab application and web logs for requests or rendered content matching known Kroki XSS patterns.
- Review user activity for unexpected actions performed shortly after viewing diagrams, especially by privileged accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0050.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/387023 | Broken Link |
| https://hackerone.com/reports/1731349 | Permissions Required |
| https://gitlab.com/gitlab-org/cves/-/blob/master/2023/CVE-2023-0050.json | Vendor Advisory |
| https://gitlab.com/gitlab-org/gitlab/-/issues/387023 | Broken Link |
| https://hackerone.com/reports/1731349 | Permissions Required |
Track CVE-2023-0050 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-0050), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.