CVE-2025-6601

GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.4.3, and 18.5 before 18.5.1 that under certain conditions could have allowed authenticated users to gain unauthorized project access by exploiting the access request approval workflow.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*

History

28 Oct 2025, 13:38

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:18.5.0:*:*:*:enterprise:*:*:*
First Time Gitlab
Gitlab gitlab
References () https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/ - () https://about.gitlab.com/releases/2025/10/22/patch-release-gitlab-18-5-1-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/551267 - () https://gitlab.com/gitlab-org/gitlab/-/issues/551267 - Broken Link
References () https://hackerone.com/reports/3209641 - () https://hackerone.com/reports/3209641 - Permissions Required

27 Oct 2025, 00:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-27 00:15

Updated : 2025-10-28 13:38


NVD link : CVE-2025-6601

Mitre link : CVE-2025-6601

CVE.ORG link : CVE-2025-6601


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-840

Business Logic Errors