GitLab EE Prompt Injection Vulnerability in Merge Request Comments Allows Information Leakage from Confidential Issues

Vulnerability

A prompt injection vulnerability has been identified in GitLab Enterprise Edition (EE) versions 17.9 prior to 18.3.6, 18.4 prior to 18.4.4, and 18.5 prior to 18.5.2. This vulnerability could have allowed an authenticated user to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure from confidential issues.

Remediation

Users are advised to upgrade to GitLab EE versions 18.5.2, 18.4.4, or 18.3.6.

Added: Nov 15, 2025, 8:24 AM
Updated: Nov 15, 2025, 8:24 AM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
7.7
relevance
1.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.