HomeinetGitLab fixes multiple vulnerabilities that allow arbitrary code execution

GitLab fixes multiple vulnerabilities that allow arbitrary code execution

GitLab has released urgent security updates for multiple versions of its platform, addressing eight vulnerabilities that could allow arbitrary code execution and unauthorized access to self-managed installations.

See also: GitLab fixed 10 security vulnerabilities

GitLab fixes multiple vulnerabilities that allow arbitrary code execution

Upgraded versions 18.7.1, 18.6.3 and 18.5.5 were implemented on GitLab.com on January 7, 2026, while customers with self-hosted environments are urged to upgrade immediately.

The most critical vulnerability, CVE-2025-9222 , affects Community and Enterprise editions and has a CVSS score of 8.7. It is a cached cross-site scripting (XSS) flaw in GitLab Flavored Markdown placeholders, which could allow authenticated attackers to execute malicious code in victims' browsers.

The affected versions range from 18.2.2 to 18.7.0, covering a large number of installations. A second high-severity issue, CVE-2025-13761, concerns the Web IDE component and has a CVSS score of 8.0.

See also: GitLab Security Update – Fixing Multiple Vulnerabilities

gitlab cisa

This vulnerability allows malicious code execution by misleading logged-in users to malicious websites, resulting in session hijacking and unauthorized access to repositories. Enterprise Edition customers are additionally at risk from CVE-2025-13772, a lack of authorization checking bug in the Duo Workflows API, which allows authenticated users to access AI model settings in unauthorized namespaces.

This vulnerability was discovered internally by GitLab engineer Jessie Young and has a CVSS score of 7.1.

The vulnerabilities were reported through GitLab's HackerOne bug bounty program, with researcher yvvdwf credited with discovering the critical XSS vulnerability.

GitLab follows a 30-day disclosure policy, whereby detailed issue reports are made public to the tracking system after fixes are released

See also: Serious vulnerabilities in GitLab allow installations to be taken down

GitLab fixes multiple vulnerabilities that allow arbitrary code execution

Administrators of self-managed GitLab installations are advised to consult the official upgrade documentation and subscribe to the GitLab security updates RSS feed to receive timely notifications of future patches.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS