GitLab has remediated a CVE-2025-9957 authorization bypass vulnerability affecting GitLab Community and Enterprise editions versions 11.2 through 18.11.0, which allowed authenticated project owners to circumvent group fork prevention controls through improper authorization checks. The vulnerability requires high privileges to exploit, as the attacker must already possess project owner permissions, and operates over the network with low attack complexity. The CVSS score of 2.7 reflects low severity with limited impact, specifically limited integrity violation and no confidentiality or availability effects. Currently, there is no evidence of active exploitation in the wild, no public exploit code is available, and the vulnerability has not been prioritized for federal inclusion in the Known Exploited Vulnerabilities catalog. Community attention remains minimal as indicated by the low EPSS score of 0.0001, suggesting this issue poses minimal risk in practical threat environments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 18.10, < 18.10.4CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 18.11, < 18.11.1CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 11.2, < 18.9.6CPE match | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | ||
>= 11.2.0, < 18.9.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* | ||
>= 11.2.0, < 18.9.6CPE matchmatch criteria | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.