PT-2025-50581 · Gitlab · Gitlab Ce/Ee

Yvvdwf

·

Published

2025-12-10

·

Updated

2025-12-11

·

CVE-2025-8405

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 17.1 through 18.4.6 GitLab CE/EE versions 18.5 through 18.5.4 GitLab CE/EE versions 18.6 through 18.6.2
Description An authenticated user could perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays. The issue affects GitLab CE/EE.
Recommendations Update GitLab CE/EE to a version after 18.4.6. Update GitLab CE/EE to a version after 18.5.4. Update GitLab CE/EE to a version after 18.6.2.

Exploit

Fix

Improper Encoding or Escaping of Output

Weakness Enumeration

Related Identifiers

BDU:2025-15872
BIT-GITLAB-2025-8405
CVE-2025-8405

Affected Products

Gitlab Ce/Ee