Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data

Multiple GitLab Vulnerabilities Let Attackers Inject Malicious Prompts to Steal Sensitive Data

Posted on November 13, 2025November 13, 2025 By CWS

GitLab has launched pressing safety patches addressing a number of vulnerabilities affecting each the Group Version and the Enterprise Version.

The corporate launched variations 18.5.2, 18.4.4, and 18.3.6 to repair vital safety points that would enable attackers to compromise delicate info and bypass entry controls.

Essentially the most regarding vulnerability entails immediate injection assaults in GitLab Duo’s evaluate function. Attackers can inject hidden malicious prompts immediately into merge request feedback.

These hidden directions trick the AI system into leaking delicate info from confidential points. This vulnerability impacts GitLab Enterprise Version variations 17.9 and later, doubtlessly exposing categorised challenge knowledge to unauthorized customers.

Past immediate injection, GitLab patched 9 extra vulnerabilities starting from excessive to low severity.

CVE IDVulnerability TitleTypeSeverityCVSS ScoreCVE-2025-11224Cross-site scripting situation in k8s proxyXSSHigh7.7CVE-2025-11865Incorrect Authorization situation in workflowsAuthorization BypassMedium6.5CVE-2025-2615Information Disclosure situation in GraphQL subscriptionsInformation DisclosureMedium4.3CVE-2025-7000Information Disclosure situation in entry controlInformation DisclosureMedium4.3CVE-2025-6945Prompt Injection situation in GitLab Duo reviewPrompt InjectionLow3.5CVE-2025-6171Information Disclosure situation in packages API endpointInformation DisclosureLow3.1CVE-2025-11990Client Facet Path Traversal situation in department namesPath TraversalLow3.1CVE-2025-7736Improper Entry Management situation in GitLab PagesAccess ControlLow3.1CVE-2025-12983Denial of service situation in markdownDenial of ServiceLow3.1

A cross-site scripting (XSS) vulnerability within the Kubernetes proxy permits authenticated customers to execute malicious scripts, affecting variations 15.10 and later.

An authorization bypass in workflows lets customers take away AI flows belonging to different customers, compromising workflow integrity. Info disclosure vulnerabilities additionally pose critical dangers.

Attackers can entry delicate knowledge by means of a number of vectors: blocked customers establishing GraphQL subscriptions, unauthorized viewing of department names by means of entry management weaknesses, and data leakage through the packages API endpoint, even when repository entry is disabled.

Extra vulnerabilities embrace path-traversal points affecting department names, improper entry management in GitLab Pages that enables OAuth authentication bypasses, and denial-of-service assaults through specifically crafted Markdown content material.

GitLab strongly recommends upgrading to the patched variations instantly. The corporate has already up to date GitLab.com, and GitLab Devoted clients require no motion.

Self-managed installations should prioritize quick upgrades, as these vulnerabilities immediately have an effect on buyer knowledge safety. The patches embrace database migrations which will have an effect on improve processes.

Single-node situations will expertise downtime throughout updates, whereas multi-node installations can implement zero-downtime upgrades utilizing correct procedures.

GitLab researchers found most vulnerabilities by means of the HackerOne bug bounty program. The corporate commits to releasing safety particulars 30 days after every patch on its public situation tracker.

All affected organizations ought to evaluate their present GitLab variations and deploy patches directly to guard towards these escalating safety threats.

Observe us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Attackers, Data, GitLab, Inject, Malicious, Multiple, Prompts, Sensitive, Steal, Vulnerabilities

Post navigation

Previous Post: Fake Chrome Extension “Safery” Steals Ethereum Wallet Seed Phrases Using Sui Blockchain
Next Post: Tens of Thousands of Malicious NPM Packages Distribute Self-Replicating Worm

Related Posts

Hackers Leveraging Microsoft Edge Internet Explorer Mode to Gain Access to Users’ Devices Hackers Leveraging Microsoft Edge Internet Explorer Mode to Gain Access to Users’ Devices Cyber Security News
Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks Cyber Security News
Amazon EKS Vulnerabilities Exposes Sensitive AWS Credentials and Escalate Privileges Amazon EKS Vulnerabilities Exposes Sensitive AWS Credentials and Escalate Privileges Cyber Security News
Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address Let’s Encrypt Started to Issue SSL/TLS Certificate for IP Address Cyber Security News
Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach Qilin RaaS Exposed 1 Million Files and 2 TB of Data Linked to Korean MSP Breach Cyber Security News
Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access Hackers Actively Attacking Cisco and Palo Alto Networks VPN Gateways to Gain Login Access Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Top Fraud Detection Tools for 2026
  • Microsoft Urges Action on Critical Windows Updates
  • Citrix NetScaler Threat: Immediate Action Required
  • Iranian Hackers Compromise FBI Director’s Email, Attack Stryker
  • Stocks in Cybersecurity Dip as Anthropic Tests Cutting-Edge AI

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark