logo

GitLab Patch Alert: High-Severity Web IDE Flaw Exposes Private Repos

ID: 1991caf5-5a2a-5071-a9cc-3c73ea341c29

STIX ID: report--1991caf5-5a2a-5071-a9cc-3c73ea341c29

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-02-11

Date Updated: 2026-04-23

Author: Ddos

...
...

GitLab released security updates (18.8.4, 18.7.4, 18.6.6) that fix 13 vulnerabilities, including a high-severity unauthenticated token-theft flaw in the Web IDE (CVE-2025-7659, CVSS 8.0), multiple denial-of-service vectors (GraphQL overload, JSON exhaustion, markdown processing), and XSS/HTML injection issues affecting many versions back to GitLab 8.0; administrators should prioritize upgrading to protect private repositories and prevent crashes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.