CVE-2025-6945: Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge request comments.
Other sources
GitLab has remediated an issue that could have allowed an authenticated user to leak sensitive information from confidential issues by injecting hidden prompts in merge request comments.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6945?
CVE-2025-6945 is a medium severity vulnerability that allows an authenticated user to leak sensitive information.
How do I fix CVE-2025-6945?
To fix CVE-2025-6945, upgrade GitLab EE to version 18.5.2 or later.
What versions of GitLab EE are affected by CVE-2025-6945?
CVE-2025-6945 affects GitLab EE versions from 17.9 up to 18.3.6, and version 18.4.4.
Can CVE-2025-6945 be exploited remotely?
CVE-2025-6945 requires user authentication, so it cannot be exploited remotely without authenticated access.
What kind of information can be leaked due to CVE-2025-6945?
CVE-2025-6945 can potentially leak sensitive information from confidential issues in GitLab.