Skip to content
  • Blog Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data

Posted on November 13, 2025November 13, 2025 By CWS

GitLab has launched pressing safety patches addressing a number of vulnerabilities affecting each the Group Version and the Enterprise Version.

The corporate launched variations 18.5.2, 18.4.4, and 18.3.6 to repair vital safety points that would enable attackers to compromise delicate info and bypass entry controls.

Essentially the most regarding vulnerability entails immediate injection assaults in GitLab Duo’s evaluate function. Attackers can inject hidden malicious prompts immediately into merge request feedback.

These hidden directions trick the AI system into leaking delicate info from confidential points. This vulnerability impacts GitLab Enterprise Version variations 17.9 and later, doubtlessly exposing categorised challenge knowledge to unauthorized customers.

Past immediate injection, GitLab patched 9 extra vulnerabilities starting from excessive to low severity.

CVE IDVulnerability TitleTypeSeverityCVSS ScoreCVE-2025-11224Cross-site scripting situation in k8s proxyXSSHigh7.7CVE-2025-11865Incorrect Authorization situation in workflowsAuthorization BypassMedium6.5CVE-2025-2615Information Disclosure situation in GraphQL subscriptionsInformation DisclosureMedium4.3CVE-2025-7000Information Disclosure situation in entry controlInformation DisclosureMedium4.3CVE-2025-6945Prompt Injection situation in GitLab Duo reviewPrompt InjectionLow3.5CVE-2025-6171Information Disclosure situation in packages API endpointInformation DisclosureLow3.1CVE-2025-11990Client Facet Path Traversal situation in department namesPath TraversalLow3.1CVE-2025-7736Improper Entry Management situation in GitLab PagesAccess ControlLow3.1CVE-2025-12983Denial of service situation in markdownDenial of ServiceLow3.1

A cross-site scripting (XSS) vulnerability within the Kubernetes proxy permits authenticated customers to execute malicious scripts, affecting variations 15.10 and later.

An authorization bypass in workflows lets customers take away AI flows belonging to different customers, compromising workflow integrity. Info disclosure vulnerabilities additionally pose critical dangers.

Attackers can entry delicate knowledge by means of a number of vectors: blocked customers establishing GraphQL subscriptions, unauthorized viewing of department names by means of entry management weaknesses, and data leakage through the packages API endpoint, even when repository entry is disabled.

Extra vulnerabilities embrace path-traversal points affecting department names, improper entry management in GitLab Pages that enables OAuth authentication bypasses, and denial-of-service assaults through specifically crafted Markdown content material.

GitLab strongly recommends upgrading to the patched variations instantly. The corporate has already up to date GitLab.com, and GitLab Devoted clients require no motion.

Self-managed installations should prioritize quick upgrades, as these vulnerabilities immediately have an effect on buyer knowledge safety. The patches embrace database migrations which will have an effect on improve processes.

Single-node situations will expertise downtime throughout updates, whereas multi-node installations can implement zero-downtime upgrades utilizing correct procedures.

GitLab researchers found most vulnerabilities by means of the HackerOne bug bounty program. The corporate commits to releasing safety particulars 30 days after every patch on its public situation tracker.

All affected organizations ought to evaluate their present GitLab variations and deploy patches directly to guard towards these escalating safety threats.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attackers, Data, GitLab, Inject, Malicious, Multiple, Prompts, Sensitive, Steal, Vulnerabilities

Post navigation

Previous Post: Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Next Post: Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm

Related Posts

Microsoft Windows Defender Firewall Vulnerabilities Let Attackers Escalate Privileges Cyber Security News
2/3 of Organizations Fear Identity Attacks, But Blind Spots Remain Cyber Security News
SCATTERED SPIDER Using Aggressive Social Engineering Techniques to Deceive IT Support Teams Cyber Security News
Microsoft Introduces Researcher in Microsoft 365 Copilot, a Secure Virtual Assistant for Your Computer Cyber Security News
INE Security Expands Across Middle East and Asia to Accelerate Cybersecurity Upskillin Cyber Security News
Microsoft’s New AI Agent Project to Detect Malware with Reverse Engineering Tools Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Silver Fox Hackers Attacking Indian Entities with Income Tax Phishing Lures
  • New Phishing Kit with AI-assisted Development Attacking Microsoft Users to Steal Logins
  • Windows Event Logs Reveal the Messy Reality Behind ‘Sophisticated’ Cyberattacks
  • Top US Accounting Firm Sax Discloses 2024 Data Breach Impacting 220,000
  • 2.5 Million+ Malicious Request From Hackers Attacking Adobe ColdFusion Servers

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2025 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark