VYPR
Unrated severityNVD Advisory· Published Jul 24, 2025· Updated Jul 24, 2025

Exposure of Sensitive Information Due to Incompatible Policies in GitLab

CVE-2025-4976

Description

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

Affected products

2
  • GitLab Inc./GitLabv52 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 17.0
    • (no CPE)range: >=17.0 <18.0.5, >=18.1 <18.1.3, >=18.2 <18.2.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1