Code Distribution Vulnerability in GitLab CE/EE by GitLab
CVE-2025-5101

5MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
27 August 2025

What is CVE-2025-5101?

A vulnerability has been identified in GitLab CE/EE that may allow an authenticated user to introduce malicious code that appears benign through manipulative behavior during the repository import process. This exploitation relies on the ambiguity between branches and tags, potentially endangering the integrity of the environment for versions prior to 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1.

Affected Version(s)

GitLab 0 < 18.1.5

GitLab 18.2 < 18.2.5

GitLab 18.3 < 18.3.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [st4nly0n](https://hackerone.com/st4nly0n) for reporting this vulnerability through our HackerOne bug bounty program
.
CVE-2025-5101 : Code Distribution Vulnerability in GitLab CE/EE by GitLab