CVE-2025-7659Patch(gitlab / gitlab)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gitlab gitlab systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to steal tokens and access private repositories by abusing incomplete validation in the Web IDE.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gitlab

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 6 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 4d ago at 3 mentions (2026-02-11); latest day: 1
  • 8 total mentions across 5 days

Affected systems

Vendors
Products
gitlab

Deep dive

Activity timeline8 mentions / 5d
01223Mentions · 2026-02-11: 3Mentions · 2026-02-13: 1Mentions · 2026-02-16: 2Mentions · 2026-02-17: 1Mentions · 2026-02-19: 1Patch / Workaround · 2026-02-11: 2Patch / Workaround · 2026-02-16: 1Patch / Workaround · 2026-02-17: 1Patch / Workaround · 2026-02-19: 1Technical Details · 2026-02-11: 2Technical Details · 2026-02-13: 1Technical Details · 2026-02-16: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 102-1102-1302-1602-1702-19
Signal classification3 categories
Patch
562.5%
General
225.0%
Disclosure
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-113
General1Patch2
2026-02-131
Disclosure1
2026-02-162
General1Patch1
2026-02-171
Patch1
2026-02-191
Patch1
Full discourse8 posts
  • iototsecnews@iototsecnews
    Patch

    GitLab の脆弱性 CVE-2025-7659 などが FIX:不正アクセス/DoS/XSS などの恐れ https://iototsecnews.jp/2026/02/11/gitlab-patches-multiple-vulnerabilities-that-enables-dos-and-cross-site-scripting-attacks/ GitLab の開発環境において、データの盗取やシステムの停止を招く恐れがある、複数の深刻な脆弱性が発生しました。この問題の原因は、Web IDEでのアクセストークン管理における検証不備や、GraphQL および JSON データの処理における不適切なリソース制限にあります。特に、Web IDE の欠陥では、ログインが必要なはずのプライベートな情報を、特定の検証プロセスを回避することで外部から取得できてしまう設計上の脆弱性が生じています。また、外部からの複雑なデータ要求に対して、サーバが過剰に応答してしまうことで、処理能力が限界に達し、システムがダウンする状況も引き起こされます。ご利用のチームは、ご注意ください。 #CVE202514560 #CVE20257659 #CVE20258099 #CVE20260958 #GitLab #Vulnerability

    Post summary

    GitLab has identified several critical vulnerabilities (CVE‑2025‑7659, etc.) that could enable unauthorized access, DoS, or XSS; a fix has been released and users are advised to apply the patch promptly.

    11000182
    484 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos GitLab ❗ CVE-2026-0958 ❗ CVE-2025-8099 ❗ CVE-2025-7659 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-gitlab-5/ https://t.co/LNCW2ywzjA

    Post summary

    The post lists three GitLab CVEs and links to an external page for more information, but provides no further details.

    00001115
    6.6K followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: 5 high resource allocation/XSS in #GitLab #CE/EE CVE-2025-7659, CVE-2025-8099, CVE-2025-14560, CVE-2026-0595 & CVE-2026-0958 CVSS: 8.0-7.3 Network based attackers can inject code to access private repositories and cause denial of service #DoS #Patch

    Post summary

    A warning about five high‑severity GitLab CVEs that enable code injection and denial‑of‑service attacks, with CVSS scores ranging from 7.3 to 8.0.

    00001234
    7.2K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2025-7659 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an una… https://www.cve.org/CVERecord?id=CVE-2025-7659

    Post summary

    GitLab has issued a patch for CVE‑2025‑7659, affecting several major release lines, to address a vulnerability that could have enabled unauthenticated exploitation.

    00010168
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A critical Origin Validation Error (CVE-2025-7659) affects `GitLab` versions prior to 18.8.4. This flaw could lead to unauthorized actions. Update `GitLab` to 18.8.4 or later. #GitLab #AppSec #CVE https://www.pulsepatch.io/posts/cve-2025-7659-gitlab-origin-validation-error

    Post summary

    GitLab CVE-2025-7659 is an origin validation flaw that can allow unauthorized actions; upgrading to version 18.8.4 or newer resolves the issue.

    0000060
    1 followersView on X
  • CRAC Learning - Tech@cracbot
    Patch

    CVE-2025-7659 (CVSS:8.0, HIGH) is Analyzed. GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 1..https://nvd.nist.gov/vuln/detail/CVE-2025-7659 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    GitLab released a patch for CVE‑2025‑7659, a high‑severity flaw affecting multiple CE/EE versions; the post does not mention PoCs, exploits, or active attacks.

    0000028
    171 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-7659 GitLab Web IDE Vulnerability Enables Unauthenticated Token... https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-7659 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet simply announces CVE‑2025‑7659 with a link to a vulnerability details page, providing no further technical or exploitation information.

    0000067
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Patch

    🟠 CVE-2025-7659 - High GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an unauthenticated user to ste... https://www.thehackerwire.com/vulnerability/CVE-2025-7659/ https://t.co/O7zz76qixT

    Post summary

    GitLab has remediated the high‑severity CVE‑2025‑7659 affecting multiple versions of its CE/EE releases; the text provides patch information but no exploitation details.

    0000063
    112 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appgitlabgitlab---
Appgitlabgitlab---

Explore more