PT-2025-29075 · Gitlab · Gitlab Ce/Ee

Published

2025-07-09

·

Updated

2025-07-25

·

CVE-2025-6168

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: GitLab EE versions 18.0 through 18.0.3 GitLab EE versions 18.1 through 18.1.1
Description: An issue allows authenticated maintainers to bypass group-level user invitation restrictions by sending crafted API requests.
Recommendations: Update to GitLab EE version 18.0.4 or later. Update to GitLab EE version 18.1.2 or later.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-09096
BIT-GITLAB-2025-6168
CVE-2025-6168

Affected Products

Gitlab Ce/Ee