Stored Cross-Site Scripting Vulnerability in GitLab Kubernetes Proxy
CVE-2025-11224
What is CVE-2025-11224?
A stored cross-site scripting vulnerability in GitLab's Kubernetes proxy functionality has been identified, allowing authenticated users to execute arbitrary scripts. This issue arises from inadequate input validation, potentially enabling malicious actors to manipulate user sessions and execute harmful scripts within the context of the affected application. The vulnerability impacts various versions of GitLab CE/EE, making it essential for users to update to the patched releases to mitigate the risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 15.10 < 18.3.6
GitLab 18.4 < 18.4.4
GitLab 18.5 < 18.5.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved