PT-2025-13000 · Gitlab · Gitlab Ce/Ee

Published

2025-03-26

·

Updated

2025-08-13

·

CVE-2025-2255

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Gitlab EE/CE versions 13.5.0 through 17.8.6 Gitlab EE/CE versions 17.9 through 17.9.3 Gitlab EE/CE versions 17.10 through 17.10.1
Description An issue has been discovered in Gitlab EE/CE for AppSec affecting certain versions. Certain error messages could allow Cross-Site Scripting attacks (XSS) for AppSec.
Recommendations For versions 13.5.0 through 17.8.6, update to version 17.8.6 or later. For versions 17.9 through 17.9.3, update to version 17.9.3 or later. For versions 17.10 through 17.10.1, update to version 17.10.1 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03519
BIT-GITLAB-2025-2255
CVE-2025-2255

Affected Products

Gitlab Ce/Ee