GitLab CE/EE Account Takeover Vulnerability via HTML Injection in Work Item Names

Vulnerability

A vulnerability allowing account takeover has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2. This issue arises from the ability of authenticated users to inject malicious HTML into work item names, potentially leading to exploitation.

Impact

Exploitation of this vulnerability could result in unauthorized account takeover.

Added: Aug 13, 2025, 9:09 PM
Updated: Aug 13, 2025, 9:09 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
5.0
exploitability
5.0
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.