An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.
2025-06-12T10:16:39.200
2025-08-08T18:23:29.080
Analyzed
CVSSv3.1: 8.7 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 18.0.2 | Yes |
| Application | gitlab | gitlab | < 18.0.2 | Yes |