PT-2025-35245 · Gitpod+1 · Gitpod+1
Mirc
·
Published
2025-08-29
·
Updated
2025-08-29
·
CVE-2025-55750
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Gitpod versions prior to main-gha.33628
Description
Gitpod, a developer platform for cloud development environments, experienced an issue where OAuth integration with Bitbucket, under specific conditions, could expose a valid Bitbucket access token via the URL fragment when a crafted link was clicked by an authenticated user. This occurred due to the way Bitbucket returned tokens and how Gitpod handled the redirect flow. The issue was limited to Bitbucket integrations and required user interaction.
Recommendations
Update to version main-gha.33628 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bitbucket
Gitpod