CVE-2026-15077
GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted content processed by the AI-assisted code review functionality.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS probability
- 0.25%
- CWE
- CWE-1427
- Published
- 2026-07-29
- Last modified
- 2026-07-29
Affected products
- GitLab GitLab
- GitLab GitLab
Weakness type
Related vulnerabilities
- CVE-2026-70331 — Microsoft Edge for iOS Spoofing Vulnerability
- CVE-2026-78379 — Consent bypass in python_repl tool via batch kwargs forwarding in Amazon Strands Agents Tools
- CVE-2026-75130 — Context7 2.1.2 Prompt Injection via Custom AI Instructions
- CVE-2026-21832 — HCL AION is affected by multiple security vulnerabilities.
- CVE-2026-18733 — Prompt injection bypasses shell tool consent gate in Strands Agents Tools
- CVE-2026-46580 — In Eclipse Theia versions prior to 1.71.0, files matching the pattern .prompts/*.prompttemplate in...
- CVE-2026-44688 — In Eclipse Theia versions prior to 1.71.0, the AI chat agent processed workspace file and directory...
- CVE-2026-44717 — MCP Calculate Server: Prompt Injection to RCE