CVE-2025-9222 is a stored cross-site scripting (XSS) vulnerability in GitLab CE/EE, affecting versions 18.2.2 through 18.5.4, 18.6 through 18.6.2, and 18.7.0. An authenticated user could exploit GitLab Flavored Markdown to inject malicious scripts. Rated as Medium severity (CVSS 5.4), it requires user interaction and could lead to limited confidentiality and integrity impacts. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.2.2, < 18.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.2.2, < 18.5.5CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
>= 18.6.0, < 18.6.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 18.6.0, < 18.6.3CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | ||
18.7.0CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:18.7.0:*:*:*:community:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.