IsItPatchedInstant security status for any software version
← All products

CVE-2025-11224

HIGH severity · CVSS 7.7 · Cross-site scripting (XSS)
7.7CVSS HIGH

Summary

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated user to execute stored cross-site scripting through improper input validation in the Kubernetes proxy functionality.

Impact & exploitability

Attack vectorNetwork
Attack complexityHigh
Privileges requiredLow
User interactionRequired
Confidentiality impactHigh
Integrity impactHigh
Availability impactNone
Exploit probability (EPSS)0%

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://about.gitlab.com/releases/2025/11/12/patch-release-gitlab-18-5-2-released/ ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC