CVE-2025-6186: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.
Other sources
GitLab has remediated an issue that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6186?
CVE-2025-6186 is classified as a high severity vulnerability due to the potential for account takeover.
How do I fix CVE-2025-6186?
To fix CVE-2025-6186, update GitLab CE/EE to version 18.1.4 or 18.2.2 or later.
Who is affected by CVE-2025-6186?
CVE-2025-6186 affects all authenticated users of GitLab CE/EE versions prior to 18.1.4 and 18.2.2.
What type of attack does CVE-2025-6186 enable?
CVE-2025-6186 enables a stored cross-site scripting (XSS) attack through malicious HTML injection in work item names.
When was CVE-2025-6186 disclosed?
CVE-2025-6186 was publicly disclosed on the GitLab issue tracker after being reported.