GitLab Patch Alert: High-Severity Web IDE Flaw Exposes Private Repos
ID: 1991caf5-5a2a-5071-a9cc-3c73ea341c29
STIX ID: report--1991caf5-5a2a-5071-a9cc-3c73ea341c29
Feed Name: securityonline.info
Threat Score
GitLab released security updates (18.8.4, 18.7.4, 18.6.6) that fix 13 vulnerabilities, including a high-severity unauthenticated token-theft flaw in the Web IDE (CVE-2025-7659, CVSS 8.0), multiple denial-of-service vectors (GraphQL overload, JSON exhaustion, markdown processing), and XSS/HTML injection issues affecting many versions back to GitLab 8.0; administrators should prioritize upgrading to protect private repositories and prevent crashes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
