CVE-2025-9642: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could allow an attacker to inject malicious content that may lead to account takeover.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed an unauthenticated user to execute actions on behalf of other users by injecting malicious content.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9642?
CVE-2025-9642 is considered a high severity vulnerability, as it allows for potential account takeover through malicious content injection.
How do I fix CVE-2025-9642?
To mitigate CVE-2025-9642, upgrade GitLab CE/EE to version 18.2.7 or later, 18.3.3 or later, or 18.4.1 or later.
Which versions of GitLab are affected by CVE-2025-9642?
CVE-2025-9642 affects all GitLab CE/EE versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1.
What types of attacks can CVE-2025-9642 lead to?
CVE-2025-9642 can lead to account takeover, allowing attackers to gain unauthorized access to user accounts.
Is there a workaround for CVE-2025-9642?
There is no specific workaround for CVE-2025-9642; upgrading to the fixed versions is the recommended solution.