CVE-2025-13781: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting missing authorization checks in GraphQL mutations.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-13781?
CVE-2025-13781 is considered a moderate severity vulnerability due to the potential for authenticated users to modify critical settings.
How do I fix CVE-2025-13781?
To fix CVE-2025-13781, upgrade to GitLab EE version 18.7.1 or later, or apply the recommended patches.
Who is affected by CVE-2025-13781?
CVE-2025-13781 affects users of GitLab EE versions 18.5.5, 18.6.3, and prior to 18.7.1.
What type of vulnerability is CVE-2025-13781?
CVE-2025-13781 is an authorization vulnerability that allows unauthorized modifications of AI feature provider settings.
What are the potential impacts of CVE-2025-13781?
The exploitation of CVE-2025-13781 could lead to unauthorized access and modification of instance-wide settings, compromising system integrity.