/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-7734

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-7734

Severity

8.7

High

CVSS V3

Summary

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing