CVE-2025-10282: GitLab Domain Confusion in gitlab Leaks API Key
Summary
bbot's gitlab.py sends the user's "gitlab" API key to on-premise GitLab instances.
If a user has configured a gitlab.com API key using this mechanism, it may be leaked to an attacker-controlled server.
Impact
A user with a "gitlab" API key configured who uses bbot to scan a malicious webserver may leak their gitlab.com API key to an untrustworthy server.
Other sources
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pip/bbotto a version that resolves this vulnerability.Fixed in 2.7.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-10282?
CVE-2025-10282 is considered a high-severity vulnerability due to its potential to disclose sensitive API keys.
How do I fix CVE-2025-10282?
To mitigate CVE-2025-10282, it is recommended to update the GitLab application to the latest version where the vulnerability is patched.
What type of attack does CVE-2025-10282 allow?
CVE-2025-10282 allows an attacker to exploit a maliciously formatted git URL to disclose a GitLab API key.
Which software is affected by CVE-2025-10282?
CVE-2025-10282 affects GitLab's gitlab module.
How can I protect against CVE-2025-10282?
To protect against CVE-2025-10282, ensure proper validation of git URLs and regularly update your GitLab installation.