logo

GitLab Patch: High-Severity XSS & AI Flaws Expose User Data

ID: 09c8c833-71a9-5308-9ce4-fcafccf9dc0d

STIX ID: report--09c8c833-71a9-5308-9ce4-fcafccf9dc0d

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Ddos

...
...

GitLab released critical security updates (18.7.1, 18.6.3, 18.5.5) addressing multiple vulnerabilities—most notably Stored XSS in Markdown (CVE-2025-9222, CVSS 8.7), Web IDE XSS (CVE-2025-13761, CVSS 8.0), and an EE Duo Workflows API authorization bypass (CVE-2025-13772, CVSS 7.1)—and urges self-managed installations to upgrade immediately; some issues affect versions as far back as 10.3.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.