CVE-2025-0555: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a user’s browser under specific conditions. This is a high severity issue (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N, 7.7). It is now mitigated in the latest release and is assigned CVE-2025-0555.
Other sources
A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-0555?
CVE-2025-0555 is classified as a high severity vulnerability due to its potential for executing arbitrary scripts in a user's browser.
How do I fix CVE-2025-0555?
To fix CVE-2025-0555, upgrade GitLab-EE to version 17.7.6 or later, 17.8.4 or later, or 17.9.1 or later.
What versions of GitLab-EE are affected by CVE-2025-0555?
CVE-2025-0555 affects GitLab-EE versions from 16.6 to 17.7.6, 17.8 to 17.8.4, and 17.9 to 17.9.1.
What kind of attacks can be executed due to CVE-2025-0555?
CVE-2025-0555 allows attackers to perform Cross Site Scripting (XSS) attacks, enabling them to execute arbitrary scripts in users' browsers.
Is CVE-2025-0555 a newly discovered vulnerability?
CVE-2025-0555 was identified as a vulnerability affecting GitLab-EE, with patches released in late 2023.