Access Control Vulnerability in GitLab EE Affecting Multiple Versions
CVE-2025-4976
What is CVE-2025-4976?
An access control vulnerability has been identified in GitLab EE that may permit unauthorized access to sensitive internal notes within GitLab Duo responses. This issue affects several versions, particularly those prior to 18.0.5, 18.1.3, and 18.2.1. Under specific circumstances, an attacker could exploit this flaw, compromising data security and privacy. It is crucial for users of affected versions to apply recommended updates promptly to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 17.0 < 18.0.5
GitLab 18.1 < 18.1.3
GitLab 18.2 < 18.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved