Medium severity4.3NVD Advisory· Published Jul 24, 2025· Updated Jun 17, 2026
CVE-2025-4976
CVE-2025-4976
Description
An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 17.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=17.0.0,<18.0.5
- cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*
- (no CPE)range: 17.0 <= versions < 18.0.5, 18.1 <= versions < 18.1.3, 18.2 <= versions < 18.2.1
- Range: 17.0 <= versions < 18.0.5, 18.1 <= versions < 18.1.3, 18.2 <= versions < 18.2.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/543905nvdBroken Link
- hackerone.com/reports/3149956nvdPermissions Required
News mentions
1- GitLab Patch Release: 18.2.1, 18.1.3, 18.0.5GitLab Security Releases · Jul 23, 2025