CVE-2025-6948: Cross-site scripting issue impacts GitLab CE/EE
An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
— GitLab
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 17.11.6Fixed in 18.0.4Fixed in 18.1.2 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 17.11.6 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.0.4 - Upgrade
Upgrade
GitLab CE/EEto a version that resolves this vulnerability.Fixed in 18.1.2
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-6948?
CVE-2025-6948 has been classified as a high severity vulnerability due to the potential for an attacker to execute actions on behalf of users.
How do I fix CVE-2025-6948?
To mitigate CVE-2025-6948, update GitLab CE/EE to version 17.11.6, 18.0.4, or 18.1.2 or later.
What versions are affected by CVE-2025-6948?
CVE-2025-6948 affects GitLab CE/EE versions before 17.11.6, 18.0.4, and 18.1.2.
What action can attackers perform due to CVE-2025-6948?
Attackers can inject malicious content that allows them to execute actions on behalf of users affected by CVE-2025-6948.
Is CVE-2025-6948 specific to any configuration?
CVE-2025-6948 can be exploited under certain conditions, making its impact dependent on the specific usage scenario.