---
id: CVE-2025-13761
title: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an
  unauthenticated user to execute arbitrary code in the context of an 
  authenticated user's br…
summary: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an
  unauthenticated user to execute arbitrary code in the context of an 
  authenticated user's br…
severity: high
cvss: 8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-79
  - CWE-79
vendor: gitlab
product: gitlab
affected:
  - 'gitlab >= 18.6.0, < 18.6.3'
  - gitlab = 18.7.0
patched:
  - gitlab 18.6.3
published: '2026-01-09'
updated: '2026-06-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-13761'
references:
  - url: >-
      https://about.gitlab.com/releases/2026/01/07/patch-release-gitlab-18-7-1-released/
    label: cve@gitlab.com
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/issues/582237'
    label: cve@gitlab.com
  - url: 'https://hackerone.com/reports/3441368'
    label: cve@gitlab.com
  - url: 'https://access.redhat.com/security/cve/CVE-2025-13761'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2428218'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-13761.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00707
epssPercentile: 0.51426
ingestedAt: '2026-06-30T13:26:50.260Z'
---

## Overview

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an  authenticated user's browser by convincing the legitimate user to visit a specially crafted webpage.

## Affected

- `gitlab >= 18.6.0, < 18.6.3`
- `gitlab = 18.7.0`

## Remediation

Upgrade past the affected range:

- `gitlab 18.6.3`
