Junglewise Threat Intelligence

CVE-2025-13874: GitLab CE/EE authorization bypass in project issues

CVE-2025-13874 · Severity: medium · CVSS 4.3 · Published 2026-05-14

Technologies: GitLab Community Edition, GitLab Enterprise Edition. Vendors: GitLab.

Executive brief

GitLab, a platform used by software teams to manage code and track project tasks, has fixed a security flaw that allowed unauthorized users to view private project issues. An individual with basic 'Guest' access could bypass security controls to read issue details in projects they were not supposed to see. This could lead to the exposure of sensitive internal project information, though it does not allow the attacker to modify or delete data.

Technical details

An authorization bypass vulnerability (CWE-639) exists in GitLab CE/EE due to improper validation of user-controlled keys. The flaw allows an authenticated attacker with low-level 'Guest' permissions to access and view issue work items in projects where they lack the necessary authorization. The attack is reachable over the network and requires no user interaction. GitLab has addressed this in versions 18.9.7, 18.10.6, and 18.11.3. The impact is limited to confidentiality, as the vulnerability does not provide write or delete access.

Affected products

  • GitLab GitLab Community Edition (CE) 15.1 to <18.9.7, 18.10 to <18.10.6, 18.11 to <18.11.3
  • GitLab GitLab Enterprise Edition (EE) 15.1 to <18.9.7, 18.10 to <18.10.6, 18.11 to <18.11.3

Timeline

  • 2026-05-13: patched: GitLab released versions 18.9.7, 18.10.6, and 18.11.3 to address the issue.
  • 2026-05-14: disclosed: Public disclosure of CVE-2025-13874.

References

Related threats