PT-2025-25289 · Gitlab · Gitlab Ce/Ee
Published
2025-06-11
·
Updated
2025-09-25
·
CVE-2025-4278
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 18.0 through 18.0.2
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions, HTML injection in the new search page could lead to account takeover. The vulnerability allows remote attackers to inject malicious code, enabling account takeovers on instances with authenticated access.
Recommendations
For GitLab CE/EE versions 18.0 through 18.0.2, update to a version newer than 18.0.2 to resolve the issue.
As a temporary workaround, consider restricting access to the new search page until a patch is available.
Avoid using the new search page in GitLab CE/EE versions 18.0 through 18.0.2 until the issue is resolved.
Exploit
Fix
DoS
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Ce/Ee