CVE-2025-9957: Improper Access Control issue in project fork relationship API impacts GitLab CE/EE
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks.
Other sources
GitLab has remediated an issue that under certain conditions could have allowed an authenticated user with project owner permissions to bypass group fork prevention settings due to improper authorization checks.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-9957?
CVE-2025-9957 has a medium severity rating due to its improper access control which can expose sensitive information.
How do I fix CVE-2025-9957?
To fix CVE-2025-9957, upgrade to GitLab CE/EE version 18.9.6, 18.10.4, or 18.11.1.
What versions are affected by CVE-2025-9957?
CVE-2025-9957 affects GitLab CE/EE versions from 11.2 before 18.9.6, 18.10 before 18.10.4, and 18.11 before 18.11.1.
Is CVE-2025-9957 applicable to both community and enterprise editions?
Yes, CVE-2025-9957 affects both GitLab Community Edition and Enterprise Edition.
What type of vulnerability is CVE-2025-9957?
CVE-2025-9957 is classified as an improper access control vulnerability.