CVE-2025-0376 is a medium-severity cross-site scripting (XSS) vulnerability in GitLab CE/EE, affecting versions 13.3 through 17.6.4, 17.7 through 17.7.3, and 17.8 through 17.8.1. This flaw allows an unauthenticated attacker to execute unauthorized actions by tricking a user into visiting a specially crafted "change page." The vulnerability has a CVSS score of 6.1, indicating a network-based attack with low complexity, requiring user interaction, and potentially leading to limited confidentiality and integrity impacts. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the security community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 13.3.0, < 17.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 13.3.0, < 17.6.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.7.0, < 17.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 17.7.0, < 17.7.4CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 17.8.0, < 17.8.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.