Authentication Bypass Vulnerability in GitLab Provides Unauthorized Access
CVE-2025-11702

8.5HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-11702?

An authentication bypass vulnerability in GitLab's Enterprise Edition has been identified, affecting multiple versions. An authenticated attacker with specific permissions could exploit this flaw to hijack project runners from other projects. This situation arises in versions 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1. GitLab has released patches to address this security issue, urging users to upgrade to the latest versions to maintain their projects' security and ensure proper permission integrity.

Affected Version(s)

GitLab 17.1 < 18.3.5

GitLab 18.4 < 18.4.3

GitLab 18.5 < 18.5.1

References

CVSS V3.1

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [iamgk808](https://hackerone.com/iamgk808) for reporting this vulnerability through our HackerOne bug bounty program
.