HIGH

CVE-2025-6948

Gitlab GitLab 2025-07-10 CVSS v3.1
CVSS
8

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

Summary dbcve.org

A content injection vulnerability in GitLab CE/EE allows authenticated attackers to inject malicious content that can be executed in the context of other users' sessions, enabling unauthorized actions to be performed on behalf of victim users. This appears to be a stored XSS or similar injection flaw affecting the web interface.

Mitigation

Upgrade GitLab to version 17.11.6, 18.0.4, or 18.1.2 or later. As a temporary measure, restrict user access and monitor for suspicious activity until patching is possible.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.52%
Probability of exploitation in next 30 days
43.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE