CVE-2025-5101 MEDIUM

CVE-2025-5101: Improper Control of Generation of Code ('Code Injection') in GitLab

Vendor Gitlab
Product GitLab
Weakness CWE-94 · Code injection
Published August 27, 2025
Last update August 27, 2025

CVSS base score

5.0/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction Required
Confidentiality None
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N

What the vulnerability does

01Description

An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.

Key dates

02Disclosure timeline

August 27, 2025 CVE published
August 27, 2025 Record updated