CVE-2025-0376 Information

Description

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

Reference

https://gitlab.com/gitlab-org/gitlab/-/issues/512603 https://hackerone.com/reports/2930243

Share on: