VYPR
Medium severity6.5NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026

CVE-2025-8770

CVE-2025-8770

Description

An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • GitLab Inc./GitLabv53 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 18.0
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=18.0.0,<18.0.6
    • (no CPE)range: >= 18.0 < 18.0.6, >= 18.1 < 18.1.4, >= 18.2 < 18.2.2
  • osv-coords
    Range: >= 18.0.0, < 18.0.6

Patches

Vulnerability mechanics

References

1

News mentions

1