PT-2025-33056 · Unknown · Gitlab Ce/Ee

Published

2025-07-17

·

Updated

2025-08-18

·

CVE-2025-7739

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: GitLab CE/EE versions 18.2 through 18.2.1
Description: An issue allows authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
Recommendations: Update to version 18.2.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2025-10984
BIT-GITLAB-2025-7739
CVE-2025-7739

Affected Products

Gitlab Ce/Ee