/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-6186

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-6186

Severity

5.4

Medium

CVSS CVSS_V3

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.

References

  • https://images.chainguard.dev/security/CGA-5fq3-gfpj-gxcc

Affected packages


Safe Source for Open Sourceâ„¢
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing