PT-2025-25289 · Gitlab · Gitlab Ce/Ee

Published

2025-06-11

·

Updated

2025-09-25

·

CVE-2025-4278

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 18.0 through 18.0.2
Description An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions, HTML injection in the new search page could lead to account takeover. The vulnerability allows remote attackers to inject malicious code, enabling account takeovers on instances with authenticated access.
Recommendations For GitLab CE/EE versions 18.0 through 18.0.2, update to a version newer than 18.0.2 to resolve the issue. As a temporary workaround, consider restricting access to the new search page until a patch is available. Avoid using the new search page in GitLab CE/EE versions 18.0 through 18.0.2 until the issue is resolved.

Exploit

Fix

DoS

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-06829
BIT-GITLAB-2025-4278
CVE-2025-4278

Affected Products

Gitlab Ce/Ee