CVE-2025-9222: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown placeholder processing.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 18.5.5Fixed in 18.6.3Fixed in 18.7.1 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.5.5 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.6.3 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.7.1
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9222?
CVE-2025-9222 has a medium severity rating due to the potential for stored cross-site scripting vulnerabilities.
How do I fix CVE-2025-9222?
To fix CVE-2025-9222, update GitLab to a version later than 18.7.1, 18.6.3, or 18.5.5.
Who is affected by CVE-2025-9222?
CVE-2025-9222 affects authenticated users of GitLab versions below 18.5.5, 18.6.3, and 18.7.1.
What type of vulnerability is CVE-2025-9222?
CVE-2025-9222 is classified as a stored cross-site scripting vulnerability that can be exploited through GitLab Flavored Markdown.
What should I do if I cannot upgrade to fix CVE-2025-9222?
If unable to upgrade, consider implementing strict input validation and output encoding to mitigate the risks associated with CVE-2025-9222.