CVE-2025-4278: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed a successful attacker to achieve account takeover by injecting code into the search page. Impacted versions GitLab CE/EE: all versions starting with 18.0 before 18.0.2. CVSS: 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4278?
CVE-2025-4278 has been classified as a high-severity vulnerability due to its potential for account takeover.
What versions of GitLab are affected by CVE-2025-4278?
CVE-2025-4278 affects all versions of GitLab CE/EE starting from 18.0 up to, but not including, 18.0.2.
How do I fix CVE-2025-4278?
To fix CVE-2025-4278, upgrade GitLab CE/EE to version 18.0.2 or later.
What types of attacks can CVE-2025-4278 enable?
CVE-2025-4278 can enable html injection attacks that could lead to unauthorized account access.
Is there a workaround for CVE-2025-4278?
There are no officially recommended workarounds for CVE-2025-4278; upgrading to the fixed version is advised.