CVE-2025-6186

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

15 Aug 2025, 16:33

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/549844 - () https://gitlab.com/gitlab-org/gitlab/-/issues/549844 - Broken Link
References () https://hackerone.com/reports/3189522 - () https://hackerone.com/reports/3189522 - Permissions Required
First Time Gitlab gitlab
Gitlab

14 Aug 2025, 13:12

Type Values Removed Values Added
Summary
  • (es) Se ha descubierto un problema en GitLab CE/EE que afecta a todas las versiones desde la 18.1 hasta la 18.1.4 y desde la 18.2 hasta la 18.2.2 que podría haber permitido a usuarios autenticados tomar el control de la cuenta inyectando HTML malicioso en los nombres de los elementos de trabajo.

13 Aug 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-13 18:15

Updated : 2025-08-15 16:33


NVD link : CVE-2025-6186

Mitre link : CVE-2025-6186

CVE.ORG link : CVE-2025-6186


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')