CVE-2025-11989: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific descriptions.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to execute unauthorized quick actions by including malicious commands in specific descriptions.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-11989?
CVE-2025-11989 has been classified as a medium-severity vulnerability.
How do I fix CVE-2025-11989?
To remediate CVE-2025-11989, update GitLab EE to version 18.5.1 or later.
What types of users are affected by CVE-2025-11989?
Authenticated users of affected GitLab EE versions may exploit CVE-2025-11989.
In which GitLab EE versions is CVE-2025-11989 present?
CVE-2025-11989 affects GitLab EE versions between 17.6 and 18.3.5, 18.4, and 18.5.
What actions could be performed due to CVE-2025-11989?
CVE-2025-11989 could allow an authenticated user to execute unauthorized quick actions via malicious commands.