Junglewise Threat Intelligence

CVE-2025-13761: GitLab Cross-Site Scripting in Web IDE

CVE-2025-13761 · Severity: high · CVSS 8 · Published 2026-01-09

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

A security vulnerability has been identified in GitLab's Web IDE, a tool used by developers to edit code directly in their browser. An attacker could trick a logged-in user into visiting a malicious webpage, allowing the attacker to execute unauthorized commands or steal sensitive information within the user's GitLab session. This could lead to unauthorized code changes or the exposure of private repository data.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in the GitLab Web IDE component. The flaw allows an unauthenticated remote attacker to execute arbitrary JavaScript in the context of an authenticated user's browser session. Exploitation requires user interaction, specifically convincing a legitimate user to visit a malicious URL (UI:R). Because the attack can bypass same-origin protections to interact with the GitLab API as the victim, it carries a high impact on confidentiality and integrity. The issue affects GitLab CE/EE versions 18.6.x before 18.6.3 and 18.7.x before 18.7.1. Patches are available in versions 18.7.1, 18.6.3, and 18.5.5.

Affected products

  • GitLab GitLab Community Edition 18.6 to 18.6.2, 18.7.0
  • GitLab GitLab Enterprise Edition 18.6 to 18.6.2, 18.7.0

Timeline

  • 2026-01-07: patched: GitLab released versions 18.7.1, 18.6.3, and 18.5.5 containing the fix.
  • 2026-01-09: disclosed: CVE-2025-13761 was published.

References

Related threats