Cross-Site Scripting and Content Security Policy Bypass in GitLab EE
CVE-2025-1763
8.7HIGH
What is CVE-2025-1763?
A vulnerability has been identified in GitLab EE which could allow attackers to execute cross-site scripting (XSS) attacks and bypass content security policies. This issue affects a range of versions prior to 17.9.7, specifically from 16.6 up until 17.11.1, under specific conditions. Users could be exposed to malicious scripts that may compromise their browser's security integrity.
Affected Version(s)
GitLab 16.6 < 17.9.7
GitLab 17.10 < 17.10.5
GitLab 17.11 < 17.11.1
References
CVSS V3.1
Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program