CVE-2025-6186

Publication date

2025-08-13 17:26:35

Family

GitLab

State

PUBLISHED

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.