HIGH
CVE-2025-4278
CVSS
8.7
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
Summary dbcve.org
HTML injection (stored XSS) vulnerability in GitLab CE/EE's new search page affecting versions 18.0 through 18.0.1. Attackers can inject malicious HTML/JavaScript through the search functionality, which when rendered could allow session hijacking or actions performed on behalf of authenticated users, leading to potential account takeover.
Mitigation
Upgrade GitLab to version 18.0.2 or later which contains the security fix for this vulnerability.
Weakness (CWE)
CWE-80
EPSS Score
10.63%
Probability of exploitation in next 30 days
95.6th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.