CVE-2025-4700: Cross-site scripting issue impacts Kubernetes Proxy in GitLab CE/EE
An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.
Other sources
GitLab has remediated an issue affecting a Kubernetes proxy feature that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-4700?
CVE-2025-4700 has been classified as a moderate severity vulnerability due to its potential to cause XSS attacks.
How do I fix CVE-2025-4700?
To fix CVE-2025-4700, upgrade GitLab CE/EE to version 18.0.5 or later, 18.1.3 or later, or 18.2.1 or later.
What versions of GitLab are affected by CVE-2025-4700?
CVE-2025-4700 affects GitLab CE/EE versions from 15.10 up to but not including 18.0.5, 18.1 up to but not including 18.1.3, and 18.2 up to but not including 18.2.1.
What type of vulnerability is CVE-2025-4700?
CVE-2025-4700 is a cross-site scripting (XSS) vulnerability that can lead to unintended content rendering.
Can I be exploited if I am using a patched version of GitLab for CVE-2025-4700?
If you are using a patched version of GitLab that is 18.0.5 or higher, 18.1.3 or higher, or 18.2.1 or higher, you are protected from the risks associated with CVE-2025-4700.