CVE-2025-11702: Missing Authorization in GitLab
GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user with specific permissions to hijack project runners from other projects.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11702?
CVE-2025-11702 is considered a medium severity vulnerability that can allow project runner hijacking.
How do I fix CVE-2025-11702?
To fix CVE-2025-11702, update your GitLab EE to version 18.5.1 or later.
Who is affected by CVE-2025-11702?
CVE-2025-11702 affects users of GitLab EE versions between 17.1 and 18.5.1, excluding the patched versions.
What types of permissions are involved in CVE-2025-11702?
CVE-2025-11702 involves authenticated users with specific permissions that can exploit the vulnerability.
Is CVE-2025-11702 being actively exploited?
As of the current information available, there is no indication of active exploitation of CVE-2025-11702.