GitLab has issued a security advisory regarding several high-risk vulnerabilities in the DevOps platform. These include two critical flaws , which allow attackers to bypass security mechanisms and execute malicious scripts in users' browsers.
See also: GitLab fixes HTML Injection flaw leading to XSS attacks

The vulnerabilities, reported as CVE-2025-0475 (CVSS score 8.7) and CVE-2025-0555 (CVSS score 7.7), affect self-managed versions of many systems. They offer opportunities for session hijacking, credential theft, and unauthorized system entry
The critical XSS vulnerability in GitLab's Kubernetes proxy affects all versions from 15.10 through 17.9.0.
Attackers who exploit this vulnerability have the ability to inject malicious JavaScript via improperly sanitized proxy responses, thereby causing DOM-based XSS attacks.
The attack vector (AV:N/AC:L/PR:L) requires network access and minimal user privileges from the attacker, however, it can lead to a complete compromise of user connections via crafted HTTP responses. With successful exploitation, attackers have the ability to:
- Steal session cookies via document.cookie export
- Modify CI/CD pipeline configurations using XMLHttpRequest
- Deploy malicious containers via Kubernetes API interactions
See also: New critical GitLab vulnerability allows arbitrary execution of CI/CD pipelines
A specific XSS vulnerability exists in the Maven Dependency Proxy and affects GitLab -EE versions 16.6 to 17.9.0 .

This flaw allows attackers to bypass Content Security Policy (CSP) by using specially crafted dependency metadata files with malicious JavaScript payloads embedded in them. This vulnerability exploits the lack of proper input validation when processing Maven artifacts.
GitLab confirms that this allows “Bypassing security checks and executing arbitrary scripts in a user’s browser under certain conditions.”
The complexity of the attack (AC:H) requires precise coordination, but allows for the privilege escalation from the Developer role to the Maintainer role.
GitLab has announced new releases 17.9.1, 17.8.4 , and 17.7.6 . Security experts warn that unpatched GitLab vulnerabilities remain prime targets for APT groups. XSS vulnerabilities are often encountered in software supply chain attacks
See also: GitLab releases fix for critical SAML bug
Arbitrary code execution is one of the most serious risks to your personal data. But what exactly is it? Essentially, it is the ability of an attacker to execute malicious software on your devices without your permission. This process can begin with a seemingly harmless action, such as opening an infected email or visiting a website with hidden traps. It is important to understand that executing arbitrary code can have far-reaching consequences, affecting your privacy and the security of your personal data. To protect yourself from such threats, stay up-to-date on modern hacking techniques and always proceed with caution in your online activities.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
