vulnerability
FreeBSD: VID-1a8c5720-e9cf-11ef-9e96-2cf05da270f3 (CVE-2025-0376): Gitlab -- Vulnerabilities
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:M/Au:S/C:C/I:C/A:N) | Feb 13, 2025 | Feb 14, 2025 | Mar 25, 2026 |
Severity
8
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:N)
Published
Feb 13, 2025
Added
Feb 14, 2025
Modified
Mar 25, 2026
Description
Gitlab reports: A CSP-bypass XSS in merge-request page Denial of Service due to Unbounded Symbol Creation Exfiltrate content from private issues using Prompt Injection A custom permission may allow overriding Repository settings Internal HTTP header leak via route confusion in workhorse SSRF via workspaces Unauthorized Incident Closure and Deletion by Planner Role in GitLab ActionCable does not invalidate tokens after revocation
Solutions
freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.