Cross-Site Scripting and Content Security Policy Bypass in GitLab EE
CVE-2025-1763

8.7HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
30 May 2025

What is CVE-2025-1763?

A vulnerability has been identified in GitLab EE which could allow attackers to execute cross-site scripting (XSS) attacks and bypass content security policies. This issue affects a range of versions prior to 17.9.7, specifically from 16.6 up until 17.11.1, under specific conditions. Users could be exposed to malicious scripts that may compromise their browser's security integrity.

Affected Version(s)

GitLab 16.6 < 17.9.7

GitLab 17.10 < 17.10.5

GitLab 17.11 < 17.11.1

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
.