CVE-2025-6186

8.7

GitLab · GitLab CE/EE

GitLab CE/EE is vulnerable to stored cross-site scripting via work item names, allowing authenticated users to perform account takeover.

Executive summary

An authenticated account takeover vulnerability in GitLab CE/EE, identified as CVE-2025-6186, poses a high risk to organizational data integrity and user security.

Vulnerability

This flaw is a stored cross-site scripting (XSS) vulnerability, classified as CWE-79, which occurs when input in work item names is not properly neutralized. An attacker with authenticated access can leverage this injection to execute malicious scripts in the context of another user's session, leading to account takeover.

Business impact

Successful exploitation allows an attacker to compromise user accounts, potentially gaining full control over internal development workflows, source code repositories, and sensitive project data. Given the CVSS score of 8.7, this vulnerability represents a significant threat to the confidentiality and integrity of the development environment, which could lead to severe reputational damage and unauthorized access to intellectual property.

Remediation

Immediate Action: Upgrade GitLab CE/EE instances to version 18.1.4, 18.2.2, or later immediately to apply the vendor-supplied security patches.

Proactive Monitoring: Review application access logs for suspicious activity involving work item modifications or unusual script execution patterns within the user interface.

Compensating Controls: Implement a Content Security Policy (CSP) to restrict the execution of unauthorized scripts and utilize a Web Application Firewall (WAF) to detect and block common XSS injection patterns.

Exploitation status

Public Exploit Available: Yes, a public proof-of-concept exists as documented in the HackerOne report linked in the CVE references.

Analyst recommendation

The vulnerability in GitLab CE/EE provides a clear path for account takeover, which is a critical security failure for any collaborative development platform. IT and security teams must prioritize the deployment of the provided patches to versions 18.1.4 or 18.2.2 to neutralize this threat. Delaying this remediation increases the risk of unauthorized access and potential compromise of critical development infrastructure.

More GitLab CVEs

Sources

Originally found and disclosed by Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty progra, per the CVE Program record.