PT-2025-46788 · Unknown · Gitlab Ce/Ee
Published
2025-11-13
·
Updated
2026-01-16
·
CVE-2025-11224
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab versions 3.1 through 7.7
Description
Multiple vulnerabilities exist in GitLab CE and EE, including Cross-Site Scripting (XSS), Information Disclosure, and Prompt Injection. These issues could potentially lead to a compromise of systems. A high-severity XSS flaw (CVE-2025-11224) specifically poses a risk of Kubernetes proxy session hijacking. The number of potentially affected devices worldwide is not specified. The API endpoints and vulnerable parameters are not specified.
Recommendations
Update to a newer version of GitLab to address these vulnerabilities. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gitlab Ce/Ee