An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that under certain conditions could have allowed an authenticated attacker to distribute malicious code that appears harmless in the web interface by taking advantage of ambiguity between branches and tags during repository imports.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/545165 | Broken Link | 
| https://hackerone.com/reports/3124199 | Permissions Required | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    02 Sep 2025, 17:47
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:18.3.0:*:*:*:enterprise:*:*:* | |
| References | () https://gitlab.com/gitlab-org/gitlab/-/issues/545165 - Broken Link | |
| References | () https://hackerone.com/reports/3124199 - Permissions Required | |
| First Time | Gitlab Gitlab gitlab | 
29 Aug 2025, 16:24
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | 
27 Aug 2025, 20:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-08-27 20:15
Updated : 2025-09-02 17:47
NVD link : CVE-2025-5101
Mitre link : CVE-2025-5101
CVE.ORG link : CVE-2025-5101
JSON object : View
Products Affected
                gitlab
- gitlab
CWE
                
                    
                        
                        CWE-94
                        
            Improper Control of Generation of Code ('Code Injection')
