GMS-2015-3: XSS via file names
File and directory names are not escaped in HTML output. If remote users can influence file or directory names, this can trigger a persistent XSS attack.
References
Detect and mitigate GMS-2015-3 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →