CVE-2025-7734: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-7734?
The severity of CVE-2025-7734 is rated as high due to its potential for user impersonation and execution of unauthorized actions.
How do I fix CVE-2025-7734?
To fix CVE-2025-7734, users should update GitLab CE/EE to the latest versions, specifically to 18.0.6, 18.1.4, or 18.2.2 or later.
Who is affected by CVE-2025-7734?
CVE-2025-7734 affects all versions of GitLab CE/EE from 14.2 to before 18.0.6, from 18.1 before 18.1.4, and from 18.2 before 18.2.2.
What types of attacks does CVE-2025-7734 allow?
CVE-2025-7734 allows attackers to execute actions on behalf of users by injecting malicious content under certain conditions.
When was CVE-2025-7734 disclosed?
CVE-2025-7734 was disclosed as a vulnerability affecting multiple versions of GitLab, emphasizing the need for immediate updates.