{"id":9725,"date":"2026-01-08T10:04:04","date_gmt":"2026-01-08T10:04:04","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/01\/08\/gitlab-patches-multiple-vulnerabilities-that-enables-arbitrary-code-execution\/"},"modified":"2026-01-08T10:04:04","modified_gmt":"2026-01-08T10:04:04","slug":"gitlab-patches-multiple-vulnerabilities-that-enables-arbitrary-code-execution","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/01\/08\/gitlab-patches-multiple-vulnerabilities-that-enables-arbitrary-code-execution\/","title":{"rendered":"GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution"},"content":{"rendered":"<p>    GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and <a href=\"https:\/\/cybersecuritynews.com\/chatgpt-atlas-exposes-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">unauthorized access<\/a> in self-managed installations.<\/p>\n<p>The updated versions 18.7.1, 18.6.3, and 18.5.5 were deployed to GitLab.com on January 7, 2026, with self-hosted customers strongly advised to upgrade immediately.<\/p>\n<p>The most severe vulnerability, CVE-2025-9222, affects GitLab Community and Enterprise Editions and has a CVSS score of 8.7.<\/p>\n<p>This stored <a href=\"https:\/\/cybersecuritynews.com\/citrix-netscaler-adc-and-gateway-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-site scripting<\/a> (XSS) flaw in GitLab Flavored Markdown placeholders could allow authenticated attackers to execute malicious code within victims\u2019 browsers.<\/p>\n<p>Impacted versions span from 18.2.2 through 18.7.0, affecting a broad range of deployments. A second high-severity issue, CVE-2025-13761, affects the Web IDE component and carries a CVSS score of 8.0.<\/p>\n<p>This flaw <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">allows attackers to execute\u00a0<a href=\"https:\/\/cybersecuritynews.com\/asus-embedded-malicious-code-vulnerability\/\" target=\"_blank\" rel=\"noopener\">malicious code<\/a>\u00a0by luring logged-in users to malicious<\/span> web pages, which can hijack sessions and lead to unauthorized access to repositories.<\/p>\n<p>Enterprise Edition customers face additional risks from CVE-2025-13772, a missing authorization bug in the Duo Workflows API that allows authenticated users to <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">access<a href=\"https:\/\/cybersecuritynews.com\/manipulate-stolen-data-corrupt-ai\/\" target=\"_blank\" rel=\"noopener\">\u00a0AI<\/a><\/span><a href=\"https:\/\/cybersecuritynews.com\/manipulate-stolen-data-corrupt-ai\/\" target=\"_blank\" rel=\"noreferrer noopener\"> model<\/a> settings from unauthorized namespaces.<\/p>\n<p>Discovered internally by GitLab engineer Jessie Young, this flaw carries a CVSS score of 7.1.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-additional-vulnerabilities-and-impact\"><strong>Additional Vulnerabilities and Impact<\/strong><\/h2>\n<p>The security update also addresses medium-severity issues, including <a href=\"https:\/\/cybersecuritynews.com\/teamviewer-dex-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">denial-of-service<\/a> vulnerabilities in import functionality (CVE-2025-10569).<\/p>\n<p>Insufficient access controls in GraphQL mutations that could allow unauthorized runner modifications (CVE-2025-11246).<\/p>\n<p>A low-severity information disclosure bug in Mermaid diagram rendering (CVE-2025-3950) completes the patch set.<\/p>\n<p>GitLab\u2019s security team emphasizes that all deployment types, Omnibus packages, source code installations, and Helm charts require immediate updating.<\/p>\n<p>Single-node instances will experience downtime during upgrades due to mandatory database migrations. At the same time, multi-node deployments can achieve <a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">zero-downtime<\/a> updates following proper procedures.<\/p>\n<p>The vulnerabilities were reported <span style=\"box-sizing: border-box; margin: 0px; padding: 0px;\">via GitLab\u2019s HackerOne\u00a0<a href=\"https:\/\/cybersecuritynews.com\/what-is-bug-bounty-program-why-organization-needs-them\/\" target=\"_blank\" rel=\"noreferrer noopener\">bug bounty\u00a0program<\/a>, with researcher yvvdwf credited with<\/span> discovering the critical XSS flaw.<\/p>\n<p>GitLab maintains a 30-day disclosure policy, under which detailed issue reports become public on its tracker after the <a href=\"https:\/\/about.gitlab.com\/releases\/2026\/01\/07\/patch-release-gitlab-18-7-1-released\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">patch release<\/a>.<\/p>\n<p>Self-managed GitLab administrators should consult the official update documentation and subscribe to GitLab\u2019s security release RSS feed for future patch notifications.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/gitlab-code-execution-vulnerabilities\/\">GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/gitlab-code-execution-vulnerabilities\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>GitLab Patches Multiple Vulnerabilities that Enables Arbitrary Code Execution GitLab has released emergency security patches for multiple versions of its platform, addressing eight vulnerabilities that could enable arbitrary code execution and unauthorized access in self-managed installations. The updated versions 18.7.1, 18.6.3, and 18.5.5 were deployed to GitLab.com on January 7, 2026, with self-hosted customers strongly [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648],"tags":[130],"class_list":["post-9725","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9725"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=9725"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/9725\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=9725"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=9725"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=9725"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}