PT-2025-30634 · Gitlab · Gitlab Ce/Ee

Published

2025-07-23

·

Updated

2025-08-08

·

CVE-2025-4976

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 17.0 through 18.0.4 GitLab EE versions 18.1 through 18.1.2 GitLab EE versions 18.2 through 18.2.0
Description An issue exists in GitLab EE that, under certain circumstances, could allow an attacker to access internal notes in GitLab Duo responses.
Recommendations Update to GitLab EE version 18.0.5 or later. Update to GitLab EE version 18.1.3 or later. Update to GitLab EE version 18.2.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BDU:2025-09116
BIT-GITLAB-2025-4976
CVE-2025-4976

Affected Products

Gitlab Ce/Ee