CVE-2025-7734

HIGH LAB

GitLab CE/EE <18.0.6-18.2.2 - Code Injection

Title source: llm

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.

Exploits (1)

github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2025-7734

Scores

CVSS v3 8.7
EPSS 0.0005
EPSS Percentile 16.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N

Lab Environment

EIP LAB Lab screenshot
vulnerable docker pull ghcr.io/exploitintel/cve-2025-7734-vulnerable:latest
COMMUNITY
docker pull gitlab/gitlab-ce:18.0.5-ce.0

Details

CWE
CWE-79
Status published
Products (1)
gitlab/gitlab 14.2.0 - 18.0.6 (2 CPE variants)
Published Aug 13, 2025
Tracked Since Feb 18, 2026