Medium severity4.3NVD Advisory· Published Nov 26, 2025· Updated Jun 17, 2026
CVE-2025-6195
CVE-2025-6195
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Range: from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1
from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1+ 3 more
- (no CPE)range: from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 13.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=13.7.0,<18.4.5
- cpe:2.3:a:gitlab:gitlab:18.6.0:*:*:*:enterprise:*:*:*
Patches
Vulnerability mechanics
References
3- gitlab.com/gitlab-org/gitlab/-/issues/549937nvdBroken Link
- hackerone.com/reports/3155693nvdPermissions Required
- about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/nvd
News mentions
1- GitLab Patch Release: 18.6.1, 18.5.3, 18.4.5GitLab Security Releases · Nov 26, 2025