{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-15387",
        "assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
        "state": "PUBLISHED",
        "assignerShortName": "GitLab",
        "dateReserved": "2026-07-10T10:13:06.416Z",
        "datePublished": "2026-08-26T13:36:05.088Z",
        "dateUpdated": "2026-08-26T13:36:05.088Z"
    },
    "containers": {
        "cna": {
            "title": "Acceptance of Extraneous Untrusted Data With Trusted Data in GitLab",
            "descriptions": [
                {
                    "lang": "en",
                    "value": "GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with developer-role permissions could have influenced the execution environment of Pipeline Execution Policy enforcement jobs, due to improper handling of job dependencies."
                }
            ],
            "affected": [
                {
                    "vendor": "GitLab",
                    "product": "GitLab",
                    "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
                    "cpes": [
                        "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
                    ],
                    "versions": [
                        {
                            "version": "19.1",
                            "status": "affected",
                            "lessThan": "19.1.7",
                            "versionType": "semver"
                        },
                        {
                            "version": "19.2",
                            "status": "affected",
                            "lessThan": "19.2.5",
                            "versionType": "semver"
                        },
                        {
                            "version": "19.3",
                            "status": "affected",
                            "lessThan": "19.3.1",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "description": "CWE-349: Acceptance of Extraneous Untrusted Data With Trusted Data",
                            "cweId": "CWE-349",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://gitlab.com/gitlab-org/gitlab/-/work_items/605632"
                },
                {
                    "url": "https://hackerone.com/reports/3754358",
                    "name": "HackerOne Bug Bounty Report #3754358",
                    "tags": [
                        "technical-description",
                        "exploit",
                        "permissions-required"
                    ]
                },
                {
                    "url": "https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-3-1-released/"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_1": {
                        "version": "3.1",
                        "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
                        "attackVector": "NETWORK",
                        "attackComplexity": "LOW",
                        "privilegesRequired": "LOW",
                        "userInteraction": "NONE",
                        "scope": "UNCHANGED",
                        "confidentialityImpact": "NONE",
                        "integrityImpact": "LOW",
                        "availabilityImpact": "NONE",
                        "baseScore": 4.3,
                        "baseSeverity": "MEDIUM"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Upgrade to versions 19.1.7, 19.2.5, 19.3.1 or above."
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Thanks [3nvz](https://hackerone.com/3nvz) for reporting this vulnerability through our HackerOne bug bounty program",
                    "type": "finder"
                }
            ],
            "providerMetadata": {
                "orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
                "shortName": "GitLab",
                "dateUpdated": "2026-08-26T13:36:05.088Z"
            }
        }
    }
}