CVE-2025-9825: Missing Authorization in GitLab
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.
Other sources
GitLab has remediated an issue that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.Impacted Versions: GitLab CE/EE: all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2CVSS: 5.0 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N)
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9825?
CVE-2025-9825 is classified as a medium-severity vulnerability due to unauthorized access to sensitive CI/CD variables.
How do I fix CVE-2025-9825?
To mitigate CVE-2025-9825, upgrade GitLab to version 18.2.8, 18.3.4, or 18.4.2.
Who is affected by CVE-2025-9825?
CVE-2025-9825 affects all GitLab CE/EE versions from 13.7 to 18.2.8 and versions 18.3 prior to 18.3.4 and 18.4 prior to 18.4.2.
What type of vulnerability is CVE-2025-9825?
CVE-2025-9825 is an information disclosure vulnerability that allows unauthorized users to access sensitive data.
What impact does CVE-2025-9825 have on users?
CVE-2025-9825 may allow authenticated users without project membership to view sensitive manual CI/CD variables, potentially leading to data leaks.