Executive brief
GitLab has fixed a high-severity security flaw in its Community and Enterprise editions that could allow a logged-in user to execute malicious scripts in the browsers of other users. This occurs when the platform processes specially formatted text (Markdown) used in comments, issues, or descriptions. If exploited, an attacker could potentially steal session information or perform unauthorized actions on behalf of other users, including administrators.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in GitLab CE/EE due to improper neutralization of input during the processing of GitLab Flavored Markdown (GLFM) placeholders. An authenticated attacker can exploit this by injecting malicious scripts into Markdown-enabled fields (such as issue descriptions or comments). When other users view the affected content, the script executes in their browser context. This vulnerability is assigned a CVSS score of 8.7 because it allows for a scope change (S:C), potentially leading to full compromise of the victim's session. The issue is fixed in versions 18.5.5, 18.6.3, and 18.7.1.
Affected products
- GitLab GitLab Community Edition (CE) 18.2.2 to 18.5.4, 18.6.0 to 18.6.2, 18.7.0
- GitLab GitLab Enterprise Edition (EE) 18.2.2 to 18.5.4, 18.6.0 to 18.6.2, 18.7.0
Timeline
- 2026-01-07: patched: GitLab released versions 18.7.1, 18.6.3, and 18.5.5 containing the fix.
- 2026-01-09: disclosed: Public disclosure of CVE-2025-9222.
References
- https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/
- https://gitlab.com/gitlab-org/gitlab/-/issues/562561
- https://hackerone.com/reports/3297483
- https://access.redhat.com/security/cve/CVE-2025-9222
- https://bugzilla.redhat.com/show_bug.cgi?id=2428222
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-9222.json