CVE-2025-2867
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Mar 27, 2025
CWE ID 94
Summary
CVE-2025-2867 is a vulnerability affecting GitLab Duo with Amazon Q. This issue, present in versions 17.8 before 17.8.6, 17.9 before 17.9.3, and 17.10 before 17.10.1, allows a maliciously crafted input to manipulate AI-assisted development features. The consequence of this manipulation could potentially expose sensitive project data to unauthorized users, posing a significant security risk. GitLab urges users to upgrade to the patched versions to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.