Vulnerability record · CVE-2023-2164 · published 2 August 2023
CVE-2023-2164: GitLab WebIDE beta stored XSS via crafted URL
Gitlab · Gitlab
GitLab versions from 15.9 up to the fixed releases (16.0.8, 16.1.3, 16.2.2) contain a stored cross-site scripting flaw in the WebIDE beta. An attacker can inject script that executes when a victim interacts with a crafted URL, letting the attacker run code in the victim's GitLab session context.
Description
An issue has been discovered in GitLab affecting all versions starting from 15.9 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to trigger a stored XSS vulnerability via user interaction with a crafted URL in the WebIDE beta.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Automated analysis
medium priorityCVSS rates it medium (5.4) and it requires authentication plus user interaction, but the very high EPSS score raises the practical risk.
What it is
GitLab versions from 15.9 up to the fixed releases (16.0.8, 16.1.3, 16.2.2) contain a stored cross-site scripting flaw in the WebIDE beta. An attacker can inject script that executes when a victim interacts with a crafted URL, letting the attacker run code in the victim's GitLab session context.
Impact
Successful exploitation lets an attacker execute arbitrary script in the victim's browser under the GitLab origin, enabling session or token theft and actions performed as the victim. The CVSS scope change (S:C) means impact can extend beyond the vulnerable component.
Attack surface
Reached over the network through the WebIDE beta; the vector requires low privileges (PR:L) and user interaction (UI:R), so the attacker needs an authenticated account and must get a victim to open a crafted URL.
Exploitation
Not listed in CISA KEV and no public exploit tag is present in the references, but EPSS is high (0.64975, 99.2nd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Upgrade GitLab to 16.0.8, 16.1.3, or 16.2.2 (or later) to remediate the flaw.
- If immediate upgrade is not possible, disable or restrict access to the WebIDE beta feature.
- Apply output encoding and sanitization for user-supplied content rendered in the WebIDE.
- Enforce a strict Content Security Policy to limit script execution from injected content.
- Review GitLab accounts and tokens for signs of compromise after suspected exposure.
Detection
- Search GitLab access and application logs for requests to WebIDE beta endpoints containing suspicious script payloads in URL parameters.
- Monitor for anomalous GitLab session activity or token usage following WebIDE access.
- Inspect browser or proxy logs for crafted URLs matching known XSS patterns targeting GitLab WebIDE.
- Alert on unexpected changes to projects or settings made by accounts that recently used the WebIDE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/407783 | Broken Link |
| https://hackerone.com/reports/1940598 | Permissions Required |
| https://gitlab.com/gitlab-org/gitlab/-/issues/407783 | Broken Link |
| https://hackerone.com/reports/1940598 | Permissions Required |
Track CVE-2023-2164 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-2164), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.