GitLab CE/EE Issue Deletion Vulnerability for Authenticated Users with Specific Roles

Vulnerability

A vulnerability exists in GitLab CE/EE versions 17.7 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2. Under certain conditions, this vulnerability could have allowed authenticated users with specific roles and permissions to delete issues, including confidential ones, by inviting users with a certain role.

Impact

Exploitation of this vulnerability could lead to unauthorized deletion of issues, including those marked as confidential.

Added: Aug 13, 2025, 10:13 PM
Updated: Aug 13, 2025, 10:13 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.