VYPR
High severity8.7NVD Advisory· Published Feb 12, 2025· Updated Jun 17, 2026

CVE-2025-0376

CVE-2025-0376

Description

An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.

Affected products

239

Patches

Vulnerability mechanics

References

2

News mentions

1