CVE-2025-1763: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
Other sources
An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user’s browser under specific conditions, affecting all versions from 16.6 prior to 17.9.7, 17.10 prior to 17.10.5, and 17.11 prior to 17.11.1. This is a high severity issue (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N, 8.7). It is now mitigated in the latest release and is assigned CVE-2025-1763.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1763?
CVE-2025-1763 has been rated with a severity level that indicates a significant risk due to its potential for cross-site scripting and content security policy bypass.
How do I fix CVE-2025-1763?
To fix CVE-2025-1763, you should upgrade GitLab EE to version 17.9.7 or later, 17.10.5 or later, or 17.11.1 or later.
What versions are affected by CVE-2025-1763?
CVE-2025-1763 affects all versions of GitLab EE from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.
What type of attack does CVE-2025-1763 enable?
CVE-2025-1763 enables a cross-site scripting attack that can lead to unauthorized actions being executed in a user's browser.
Is there a workaround for CVE-2025-1763?
There are no known workarounds for CVE-2025-1763; upgrading to a patched version is necessary to mitigate the vulnerability.