PT-2025-46788 · Unknown · Gitlab Ce/Ee

Published

2025-11-13

·

Updated

2026-01-16

·

CVE-2025-11224

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab versions 3.1 through 7.7
Description Multiple vulnerabilities exist in GitLab CE and EE, including Cross-Site Scripting (XSS), Information Disclosure, and Prompt Injection. These issues could potentially lead to a compromise of systems. A high-severity XSS flaw (CVE-2025-11224) specifically poses a risk of Kubernetes proxy session hijacking. The number of potentially affected devices worldwide is not specified. The API endpoints and vulnerable parameters are not specified.
Recommendations Update to a newer version of GitLab to address these vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2025-11224
CVE-2025-11224

Affected Products

Gitlab Ce/Ee