CVE-2025-5101 is a medium-severity vulnerability in GitLab CE/EE versions before 18.1.5, 18.2.5, and 18.3.1. It allows an authenticated attacker to distribute malicious code disguised as harmless content during repository imports, exploiting ambiguity between branches and tags. The attack requires high privileges and user interaction, with a potential impact of high integrity compromise. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 18.1.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
< 18.1.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.2.0, < 18.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.2.0, < 18.2.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
18.3.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.