CVE-2025-12734

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

23 Dec 2025, 21:02

Type Values Removed Values Added
References () https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/ - () https://about.gitlab.com/releases/2025/12/10/patch-release-gitlab-18-6-2-released/ - Release Notes, Vendor Advisory
References () https://gitlab.com/gitlab-org/gitlab/-/issues/579573 - () https://gitlab.com/gitlab-org/gitlab/-/issues/579573 - Broken Link
References () https://hackerone.com/reports/3379381 - () https://hackerone.com/reports/3379381 - Permissions Required
First Time Gitlab
Gitlab gitlab
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

17 Dec 2025, 00:15

Type Values Removed Values Added
Summary (en) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to leak sensitive information from specifically crafted merge request titles. (en) GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into merge request titles.

11 Dec 2025, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-12-11 08:15

Updated : 2025-12-23 21:02


NVD link : CVE-2025-12734

Mitre link : CVE-2025-12734

CVE.ORG link : CVE-2025-12734


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-116

Improper Encoding or Escaping of Output