Vulnerability record · CVE-2024-1451 · published 22 February 2024
CVE-2024-1451: GitLab user profile stored XSS via crafted payload
Gitlab · Gitlab
GitLab CE/EE versions from 16.9 up to 16.9.1 fail to properly sanitize a crafted payload added to the user profile page, resulting in stored cross-site scripting. Because the payload persists and executes in victims' browsers, it can be used to act as those users, and the affected range is narrow (16.9.x before 16.9.1).
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Automated analysis
high priorityHigh CVSS (8.7) stored XSS with scope change and very high EPSS, though exploitation requires authentication and victim interaction and no KEV listing exists.
What it is
GitLab CE/EE versions from 16.9 up to 16.9.1 fail to properly sanitize a crafted payload added to the user profile page, resulting in stored cross-site scripting. Because the payload persists and executes in victims' browsers, it can be used to act as those users, and the affected range is narrow (16.9.x before 16.9.1).
Impact
An attacker can run arbitrary script in the context of a victim's GitLab session, performing actions on the victim's behalf and potentially reading data the victim can access. The CVSS scope change (S:C) reflects impact beyond the vulnerable component.
Attack surface
Reached over the network through the user profile page; the vector requires low privileges (PR:L) and user interaction (UI:R), meaning an authenticated attacker plants the payload and a victim must view the affected profile content.
Exploitation
Not listed in CISA KEV and no public exploit references are tagged in the record, but EPSS is high at roughly 0.51 (98.9th percentile), indicating elevated predicted exploitation likelihood.
What to do
- Upgrade GitLab CE/EE to 16.9.1 or later; this is the only version boundary stated in the record.
- If immediate upgrade is not possible, restrict or monitor who can edit user profile fields and review profile content for injected markup.
- Enforce output encoding and a strict Content Security Policy on profile rendering to limit script execution.
- Audit accounts with profile-edit privileges and remove any suspicious stored content.
Detection
- Search GitLab logs and profile records for script tags, event handlers, or encoded payloads in user profile fields.
- Monitor for anomalous authenticated actions or session activity originating from users who recently viewed a modified profile.
- Alert on profile update events followed by unusual API or web actions from other accounts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/441457 | Permissions Required |
| https://hackerone.com/reports/2371126 | Permissions Required |
| https://gitlab.com/gitlab-org/gitlab/-/issues/441457 | Permissions Required |
| https://hackerone.com/reports/2371126 | Permissions Required |
Track CVE-2024-1451 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-1451), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.