CVE-2025-8405: Improper Encoding or Escaping of Output in GitLab
GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.
Other sources
GitLab has remediated a security issue that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability code flow displays.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-8405?
CVE-2025-8405 is classified as a significant security issue due to its potential for unauthorized actions by authenticated users.
How do I fix CVE-2025-8405?
To remediate CVE-2025-8405, upgrade your GitLab installation to versions 18.4.6, 18.5.4, or 18.6.2.
What kind of attacks can CVE-2025-8405 allow?
CVE-2025-8405 can allow authenticated users to perform unauthorized actions on behalf of other users by injecting malicious HTML.
Which GitLab versions are affected by CVE-2025-8405?
CVE-2025-8405 affects GitLab versions between 17.1 and 18.4.6, 18.5 and 18.5.4, and 18.6 and 18.6.2.
Who is impacted by CVE-2025-8405?
Authenticated users of GitLab versions affected by CVE-2025-8405 are at risk of exploitation.