CVE-2025-4278

Publication date

2025-06-12 10:02:25

Family

GitLab

State

PUBLISHED

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to account takeover.