HTML Injection Vulnerability in GitLab Community and Enterprise Editions
CVE-2025-8405

8.7HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
11 December 2025

What is CVE-2025-8405?

GitLab has identified a security vulnerability in its Community and Enterprise Editions that permits authenticated users to exploit the system by injecting malicious HTML into certain displays linked to vulnerability code flow. This flaw could enable them to execute unauthorized actions on behalf of other users, undermining user permissions and potentially compromising sensitive data. Versions affected include all iterations from 17.1 preceding 18.4.6, 18.5 preceding 18.5.4, and 18.6 preceding 18.6.2. Users are strongly advised to update their instances to the latest patched version to mitigate this risk.

Affected Version(s)

GitLab 17.1 < 18.4.6

GitLab 18.5 < 18.5.4

GitLab 18.6 < 18.6.2

References

CVSS V3.1

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program
.
CVE-2025-8405 : HTML Injection Vulnerability in GitLab Community and Enterprise Editions