An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.
CVSS Details
- CVSS 3.1 Base Score: 5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Freebsd | freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee | Dec 10, 2025 | Aug 29, 2025 | |
| Gitlab Gitlab | gitlab-gitlab-upgrade-latest | Aug 28, 2025 | Aug 27, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub