Skip to main content

CVE-2025-7739: GitLab Stored XSS Vulnerability

CVE-2025-7739 is a stored cross-site scripting vulnerability in GitLab CE/EE allowing authenticated users to inject malicious HTML in scoped label descriptions. This post covers technical details, affected versions, and mitigation.

Published:

CVE-2025-7739 Overview

CVE-2025-7739 is a stored cross-site scripting (XSS) vulnerability [CWE-79] affecting GitLab Community Edition (CE) and Enterprise Edition (EE). The flaw impacts all versions from 18.2 before 18.2.2. Authenticated users can inject malicious HTML content into scoped label descriptions under certain conditions. When another user views the affected label, the injected script executes in their browser context. The vulnerability allows attackers to steal session data, perform actions on behalf of victims, or pivot to further attacks within the GitLab instance.

Critical Impact

Authenticated attackers can execute arbitrary JavaScript in victim browsers by injecting malicious HTML into scoped label descriptions, enabling session theft and unauthorized actions within GitLab projects.

Affected Products

  • GitLab Community Edition (CE) versions 18.2 through 18.2.1
  • GitLab Enterprise Edition (EE) versions 18.2 through 18.2.1
  • Self-managed GitLab instances running vulnerable 18.2.x releases

Discovery Timeline

  • 2025-08-13 - CVE-2025-7739 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-7739

Vulnerability Analysis

The vulnerability resides in GitLab's handling of scoped label descriptions. Scoped labels use a key::value syntax and allow project maintainers to enforce mutually exclusive categorization. The description field associated with these labels fails to properly sanitize HTML content before rendering it in the browser. An authenticated user with permission to create or edit labels can embed malicious HTML tags and JavaScript payloads. When other users interact with issues, merge requests, or label management pages that render the description, the payload executes. The scope change in the CVSS metrics reflects that the injected script executes in the security context of the victim's session, which may span additional projects or administrative interfaces.

Root Cause

The root cause is improper neutralization of user-supplied input during web page generation [CWE-79]. GitLab's rendering pipeline for scoped label descriptions accepts HTML content without applying sufficient output encoding or a strict allowlist of safe tags. This oversight allows script-bearing markup to reach the DOM intact.

Attack Vector

Exploitation requires an authenticated account with permission to create or modify labels within a project. User interaction is required, as a victim must load a page that renders the malicious label description. The network-based attack vector and low complexity make exploitation practical in shared-tenant GitLab environments where multiple contributors have label management rights. See the GitLab Issue Discussion and HackerOne Security Report #3255849 for coordinated disclosure details.

Detection Methods for CVE-2025-7739

Indicators of Compromise

  • Scoped label descriptions containing HTML tags such as <script>, <img onerror=>, <svg onload=>, or event handler attributes
  • Unexpected outbound requests from GitLab user browsers to attacker-controlled domains shortly after viewing labels
  • Anomalous session token usage from geographies or IP ranges inconsistent with the legitimate user
  • Audit log entries showing label creation or edits by accounts that do not normally manage labels

Detection Strategies

  • Query the GitLab database or API for label descriptions containing angle brackets, javascript: URIs, or common XSS payload signatures
  • Review GitLab audit events for label create and update actions correlated with subsequent suspicious authentication events
  • Deploy a Content Security Policy (CSP) report endpoint to capture inline script violations triggered by injected payloads
  • Monitor web server access logs for GET requests to label endpoints followed by unusual API calls from the same session

Monitoring Recommendations

  • Ingest GitLab application, audit, and web server logs into a centralized SIEM for correlation of label modifications with session anomalies
  • Alert on GitLab API calls that create or edit labels with description bodies exceeding expected length or containing HTML markup
  • Track privileged user actions performed shortly after loading pages that render scoped labels

How to Mitigate CVE-2025-7739

Immediate Actions Required

  • Upgrade GitLab CE and EE to version 18.2.2 or later without delay
  • Audit existing scoped label descriptions across all projects for suspicious HTML or JavaScript content
  • Rotate session tokens and personal access tokens for users who may have viewed malicious labels
  • Review label management permissions and restrict them to trusted maintainers

Patch Information

GitLab addressed CVE-2025-7739 in version 18.2.2. Administrators of self-managed instances should apply the upgrade following GitLab's documented upgrade path. GitLab.com SaaS customers received the fix as part of the platform's managed release cycle. Refer to the GitLab Issue Discussion for patch commit references.

Workarounds

  • Restrict label creation and edit permissions to a small set of vetted maintainer accounts until patching completes
  • Enforce a strict Content Security Policy that blocks inline scripts and unauthorized external script sources
  • Manually purge or sanitize any label descriptions containing HTML markup pending upgrade
bash
# Verify installed GitLab version on a self-managed instance
sudo gitlab-rake gitlab:env:info | grep -i version

# Upgrade GitLab (Omnibus package example on Debian/Ubuntu)
sudo apt-get update && sudo apt-get install gitlab-ee=18.2.2-ee.0

# Confirm the upgrade completed successfully
sudo gitlab-ctl status

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.