GitLab Patch: High-Severity XSS & AI Flaws Expose User Data
ID: 09c8c833-71a9-5308-9ce4-fcafccf9dc0d
STIX ID: report--09c8c833-71a9-5308-9ce4-fcafccf9dc0d
Feed Name: securityonline.info
Threat Score
GitLab released critical security updates (18.7.1, 18.6.3, 18.5.5) addressing multiple vulnerabilities—most notably Stored XSS in Markdown (CVE-2025-9222, CVSS 8.7), Web IDE XSS (CVE-2025-13761, CVSS 8.0), and an EE Duo Workflows API authorization bypass (CVE-2025-13772, CVSS 7.1)—and urges self-managed installations to upgrade immediately; some issues affect versions as far back as 10.3.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
