CVE-2025-12029: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI."
Other sources
GitLab has remediated an issue that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions on behalf of another user by injecting malicious external scripts into the Swagger UI.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-12029?
CVE-2025-12029 has been classified as a high severity vulnerability due to its ability to allow unauthorized actions on behalf of another user.
How do I fix CVE-2025-12029?
To fix CVE-2025-12029, update your GitLab installation to version 18.6.2 or later.
Who is affected by CVE-2025-12029?
CVE-2025-12029 affects users of GitLab versions prior to 18.4.6, 18.5.4, and 18.6.2.
What does CVE-2025-12029 allow an attacker to do?
CVE-2025-12029 allows an unauthenticated user to inject malicious external scripts into the Swagger UI, potentially enabling unauthorized actions.
When was CVE-2025-12029 discovered?
CVE-2025-12029 was remediated in a GitLab patch that was released on December 10, 2025.