PT-2025-26936 · Gitlab · Gitlab Ce/Ee

Published

2025-06-25

·

Updated

2025-08-12

·

CVE-2025-2938

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 17.3 through 17.11.5 GitLab CE/EE versions 18.0 through 18.0.3 GitLab CE/EE versions 18.1 through 18.1.1
Description: An issue has been discovered in GitLab CE/EE that could allow authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the approval process resulted in unintended permission grants. The issue is related to incorrect handling of logical operations within the code collaboration platform.
Recommendations: GitLab CE/EE versions prior to 17.11.5 GitLab CE/EE versions prior to 18.0.3 GitLab CE/EE versions prior to 18.1.1

Exploit

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-07923
BIT-GITLAB-2025-2938
CVE-2025-2938

Affected Products

Gitlab Ce/Ee