CVE-2025-7659: Origin Validation Error in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.
Other sources
GitLab has remediated an issue that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7659?
CVE-2025-7659 is considered a high-severity vulnerability due to its potential to allow unauthenticated users to access private repositories.
How do I fix CVE-2025-7659?
To fix CVE-2025-7659, update your GitLab installation to version 18.8.4, 18.7.4, or 18.6.6.
What impact does CVE-2025-7659 have on GitLab users?
CVE-2025-7659 could allow attackers to steal tokens and gain unauthorized access to private repositories.
Which versions of GitLab are affected by CVE-2025-7659?
CVE-2025-7659 affects GitLab versions from 18.2 up to but not including 18.6.6, 18.7 up to 18.7.4, and 18.8 up to 18.8.4.
What remediation steps has GitLab taken for CVE-2025-7659?
GitLab has released patches in versions 18.6.6, 18.7.4, and 18.8.4 to remediate the incomplete validation issue.