VulnerabilityAnalyzed
CVE-2025-4278
Under certain conditions html injection in new search page could lead to account takeover.
HIGH 8.7EPSS 9.01%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.01%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
- CVSS 3.1
- 8.7 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
- EPSS
- 9.01% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-80
- Affected
- gitlab/gitlab
- Source
- cve@gitlab.com
References
- https://gitlab.com/gitlab-org/gitlab/-/issues/539198Broken Link
- https://hackerone.com/reports/3085738Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.