Skip to content
GSSA-2026-05-P6SB4WGITLAB-GSSA-2026-05-P6SB4WMay 7, 2026
5.1 Medium

Missing browser security response headers

The dashboard shipped without CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, or HSTS, leaving it exposed to clickjacking, MIME-sniffing, and missing the standard defense-in-depth layer against same-origin XSS. Fixed by adding the standard security header set in next.config.ts.

Affected (1)

  • gelhaus-solutionscontributer-checker
    • ≥ 0.0.0Fixed in 0.0.1

Mitigations

Workarounds

  • Have the reverse proxy / CDN inject the missing headers (X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy, CSP, HSTS) until 0.0.1 is deployed.
  • Until headers are in place, instruct admins/reviewers to access the dashboard only from a fresh browser tab (not embedded in third-party pages).

Solutions

  • Upgrade to 0.0.1: next.config.ts emits X-Frame-Options: DENY, X-Content-Type-Options: nosniff, Referrer-Policy: strict-origin-when-cross-origin, a CSP with frame-ancestors none and an explicit allowlist (including blob: in script-src/worker-src/media-src for Sentry replay), HSTS when behind HTTPS, plus optional Report-To/CSP report-uri pointing at the new SENTRY_CSP_ENDPOINT env var.

Exploits

  • Clickjacking: attacker hosts a page with `<iframe src="https://victim/dashboard/projects/<id>/applications/<appId>"></iframe>` positioned under a fake button. A logged-in reviewer clicks the bait button and unknowingly clicks Approve/Deny inside the framed dashboard with their auth cookie attached.

Configurations

  • All deployments of 0.0.0 — the missing headers are unconditional.

Overview

No CSP, no X-Frame-Options, no HSTS — clickjacking and MIME-sniffing were possible against the dashboard.

Severity

CVSS v4
5.1 Medium
5.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Attack vector
Network
Attack complexity
Low
Attack requirements
None
Privileges required
None
User interaction
Active
Confidentiality (vulnerable system)
None
Integrity (vulnerable system)
Low
Availability (vulnerable system)
None
Confidentiality (subsequent system)
None
Integrity (subsequent system)
None
Availability (subsequent system)
None
CVSS v3
2.6 Low
2.6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack vector
Network
Attack complexity
High
Privileges required
None
User interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Weaknesses (2)

References (5)

Credits (2)

  • Enno Gelhaus
    Remediation developer · egelhaus@ennogelhaus.de
  • Enno Gelhaus
    Finder · egelhaus@ennogelhaus.de

Context

Impacts

  • Clickjacking against approve/deny/role-change actions in the dashboard.

    CAPEC-103
  • MIME-sniffing of JSON responses as JS in older browsers.

    CAPEC-209
  • Cross-origin Referer leakage of internal IDs (project IDs, application IDs).

  • Removal of the standard defense-in-depth layer that limits exfiltration channels for any future same-origin XSS.

© 2026 Gelhaus Solutions