GitLab CE/EE Account Takeover Vulnerability via Content Injection

Vulnerability

A vulnerability allowing content injection has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 14.10 prior to 18.2.7, 18.3 prior to 18.3.3, and 18.4 prior to 18.4.1. This issue could potentially lead to account takeover.

Impact

Exploitation of this vulnerability could result in unauthorized account access, allowing an attacker to assume control of the victim's account.

Added: Sep 26, 2025, 9:23 AM
Updated: Sep 26, 2025, 2:52 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
5.0
exploitability
5.0
remediation
0.0
relevance
0.6
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.