MEDIUM
CVE-2025-7739
CVSS
5.4
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
Summary dbcve.org
GitLab CE/EE versions 18.2 through 18.2.1 contain a stored cross-site scripting (XSS) vulnerability in scoped label descriptions. Authenticated users can inject malicious HTML/JavaScript content into label descriptions that gets stored and executed when other users view those labels.
Mitigation
Upgrade GitLab to version 18.2.2 or later. Until then, restrict access to label creation/modification and sanitize any existing label descriptions from untrusted sources.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.31%
Probability of exploitation in next 30 days
24.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.