Code Distribution Vulnerability in GitLab CE/EE by GitLab
CVE-2025-5101
5MEDIUM
What is CVE-2025-5101?
A vulnerability has been identified in GitLab CE/EE that may allow an authenticated user to introduce malicious code that appears benign through manipulative behavior during the repository import process. This exploitation relies on the ambiguity between branches and tags, potentially endangering the integrity of the environment for versions prior to 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1.
Affected Version(s)
GitLab 0 < 18.1.5
GitLab 18.2 < 18.2.5
GitLab 18.3 < 18.3.1
References
CVSS V3.1
Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [st4nly0n](https://hackerone.com/st4nly0n) for reporting this vulnerability through our HackerOne bug bounty program