CVE-2025-0555
CVSS 3.1 Score 6.1 of 10 (medium)
Details
Summary
CVE-2025-0555 is a Cross-Site Scripting (XSS) vulnerability identified in GitLab Enterprise Edition (EE). Affecting versions 16.6 through 17.9, this issue enables attackers to bypass security controls and execute arbitrary scripts in a user's browser under specific conditions. By exploiting this vulnerability, attackers can gain unauthorized access to sensitive information or even take control of user sessions. This represents a significant security risk for organizations using the affected GitLab EE versions. Users are strongly advised to upgrade to the patched versions as soon as possible to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.