MEDIUM

CVE-2025-5101

Gitlab GitLab 2025-08-27 CVSS v3.1
CVSS
5

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

Summary dbcve.org

In GitLab CE/EE versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1, an authenticated attacker can exploit ambiguity between branches and tags during repository imports to make malicious code appear harmless in the web interface. The vulnerability allows attackers to import repositories where branch and tag names can be manipulated to obscure the true nature of code, deceiving users who view the repository through the web interface.

Mitigation

Upgrade GitLab to version 18.1.5, 18.2.5, 18.3.1 or later. Until upgrade is possible, restrict repository import functionality to trusted users and carefully review all imported repositories for suspicious branch/tag naming.

Weakness (CWE)

CWE-94 Code Injection

EPSS Score

0.13%
Probability of exploitation in next 30 days
2.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE