Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-4976


An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.


Published

2025-07-24T07:15:53.963

Last Modified

2025-07-28T14:14:07.687

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-213
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 18.0.5 Yes
Application gitlab gitlab < 18.1.3 Yes
Application gitlab gitlab 18.2 Yes

References