CVE-2025-7739 is a stored cross-site scripting (XSS) vulnerability affecting GitLab CE/EE versions 18.2 prior to 18.2.2. Authenticated users could inject malicious HTML into scoped label descriptions, leading to XSS. This medium-severity vulnerability (CVSS 5.4) requires user interaction and low privileges, potentially impacting confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or KEV listing, though it has received some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.2, < 18.2.2CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.2.0, < 18.2.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.2.0, < 18.2.2CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.