CVE-2025-0376: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An XSS vulnerability exists in GitLab CE/EE affecting all versions from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4 and 17.8 prior to 17.8.2 that allows an attacker to execute unauthorized actions via a change page.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0376?
CVE-2025-0376 has a high severity rating due to its potential for allowing unauthorized actions through XSS attacks.
How do I fix CVE-2025-0376?
To fix CVE-2025-0376, upgrade GitLab CE/EE to version 17.6.5 or later, 17.7.4 or later, or 17.8.2 or later.
Which versions of GitLab are affected by CVE-2025-0376?
CVE-2025-0376 affects all versions of GitLab CE/EE from 13.3 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2.
What type of vulnerability is CVE-2025-0376?
CVE-2025-0376 is an XSS (Cross-Site Scripting) vulnerability.
What can attackers do with CVE-2025-0376?
Attackers can execute unauthorized actions via a change page due to the XSS vulnerability in CVE-2025-0376.