CVE-2025-7739 Information
Aug 14, 2025
cve
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
Reference
https://gitlab.com/gitlab-org/gitlab/-/issues/556111 https://hackerone.com/reports/3255849
Related CNNVD
CNNVD-202508-1428 (Published: 2025-08-13)
Share on: