HIGH

CVE-2025-4278

Gitlab GitLab 2025-06-12 CVSS v3.1
CVSS
8.7

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.

Summary dbcve.org

HTML injection (stored XSS) vulnerability in GitLab CE/EE's new search page affecting versions 18.0 through 18.0.1. Attackers can inject malicious HTML/JavaScript through the search functionality, which when rendered could allow session hijacking or actions performed on behalf of authenticated users, leading to potential account takeover.

Mitigation

Upgrade GitLab to version 18.0.2 or later which contains the security fix for this vulnerability.

Weakness (CWE)

CWE-80

EPSS Score

10.63%
Probability of exploitation in next 30 days
95.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE