PT-2025-43140 · Gitlab · Gitlab Ce/Ee

Published

2025-10-22

·

Updated

2025-10-28

·

CVE-2025-11989

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab EE versions 17.6.0 through 18.3.5 GitLab EE versions 18.4.0 through 18.4.2 GitLab EE versions 18.5.0 through 18.5.0
Description An authenticated attacker could execute unauthorized quick actions by including malicious commands in specific descriptions. The issue involves a missing authorization check within quick actions functionality.
Recommendations Update GitLab EE to version 18.3.6 or later. Update GitLab EE to version 18.4.3 or later. Update GitLab EE to version 18.5.1 or later.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2025-14928
BIT-GITLAB-2025-11989
CVE-2025-11989

Affected Products

Gitlab Ce/Ee