GitLab has announced major security updates for Community Edition (CE) and Enterprise Edition (EE), resolving multiple vulnerabilities. Among them is a particularly serious GitLab cross-site scripting (XSS) issue.
See also: GitLab fixes HTML Injection flaw leading to XSS attacks

Fixed releases 17.8.1, 17.7.3 , and 17.6.4 are now available. GitLab strongly recommends that all self-managed installations upgrade immediately to ensure the best possible performance and security.
The most serious GitLab issue being addressed concerns improper rendering of certain file types, which leads to an XSS vulnerability (CVE-2025-0314). This vulnerability affects all versions from 17.2 to 17.6.3, 17.7 to 17.7.2, and 17.8 to 17.8.0. With a CVSS score of 8.7, this vulnerability allows attackers to inject malicious scripts into GitLab instances. This can lead to serious consequences, such as session hijacking, data theft, or unauthorized access and control of the system.
The root cause lies in the way GitLab renders certain file types using Asciidoctor, allowing attackers to embed malicious JavaScript into files that execute within the victim's browser during rendering. This could compromise user sessions or expose sensitive data.
See also: New critical GitLab vulnerability allows arbitrary execution of CI/CD pipelines
The issue was responsibly disclosed by yvvdwf, a security researcher through GitLab's HackerOne bug bounty program.

This moderate severity (CVSS: 6.4) flaw allowed developers to inject sensitive CI/CD variables under certain conditions using the CI lint feature. It affects versions starting from 17.0 before patched versions and was discovered by GitLab team member Greg Myers.
A denial of service (DoS) vulnerability with a CVSS score of 4.3 was identified in versions starting with 15.7 before the patched versions. By creating circular references between epics, attackers could exhaust system resources, disrupting services. GitLab urges all users to upgrade to the latest patched versions—17.8.1, 17.7.3, or 17.6.4—to mitigate these vulnerabilities.
To minimize risks, regularly update your GitLab presence, monitor logs for suspicious activity, educate users on recognizing phishing and timely application of updates, and conduct periodic security audits.
See also: GitLab releases fix for critical SAML bug
A Cross-Site Scripting (XSS) vulnerability, such as the one in GitLab, is a type of security vulnerability that occurs when an application allows malicious code, typically JavaScript, to be injected into web pages viewed by other users. This vulnerability can be exploited by malicious users to steal data, such as cookies, perform actions on behalf of the victim, or mislead users by displaying fake content. Proper validation and avoidance of malicious code in inputs is critical to preventing XSS attacks.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
