vulnerability

FreeBSD: VID-1a8c5720-e9cf-11ef-9e96-2cf05da270f3 (CVE-2025-0376): Gitlab -- Vulnerabilities

Severity
8
CVSS
(AV:N/AC:M/Au:S/C:C/I:C/A:N)
Published
Feb 13, 2025
Added
Feb 14, 2025
Modified
Mar 25, 2026

Description

Gitlab reports: A CSP-bypass XSS in merge-request page Denial of Service due to Unbounded Symbol Creation Exfiltrate content from private issues using Prompt Injection A custom permission may allow overriding Repository settings Internal HTTP header leak via route confusion in workhorse SSRF via workspaces Unauthorized Incident Closure and Deletion by Planner Role in GitLab ActionCable does not invalidate tokens after revocation

Solutions

freebsd-upgrade-package-gitlab-cefreebsd-upgrade-package-gitlab-ee
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.