GitLab has fixed critical vulnerabilities in Web IDE
GitLab has released emergency updates for both the Community and Enterprise Editions to address critical vulnerabilities, including a Web IDE issue that could lead to token theft. Users are strongly advised to update immediately to ensure their security.
Crius
GitLab has released emergency updates for its Community and Enterprise editions, addressing several serious vulnerabilities. Among them is a critical issue in the Web IDE with a severity rating of 8.0, which could have led to token theft and unauthorized access to private repositories.
Key Update Details
The company has issued new patches for Community Edition (CE) and Enterprise Edition (EE) in versions 18.8.4, 18.7.4, and 18.6.6. GitLab strongly recommends that all self-managed users update to the latest versions immediately. No additional action is required for GitLab Dedicated customers, as the updates have already been applied.
Major Vulnerabilities Addressed
One of the most dangerous issues is CVE-2025-7659—a high-severity vulnerability (CVSS 8.0) related to insufficient validation in the Web IDE. According to GitLab, this flaw allowed unauthenticated attackers to steal access tokens and potentially gain access to private repositories.
Other vulnerabilities addressed include denial-of-service issues, such as:
- CVE-2025-8099 — Allowed attackers to crash servers using repeated GraphQL queries.
- CVE-2026-0958 — Enabled resource exhaustion by bypassing intermediate JSON validation software.
The patch also fixes other vulnerabilities, including cross-site scripting and injection flaws (CVE-2025-14560, CVE-2026-0595), which could have enabled malicious script injection or content manipulation under certain conditions. Additionally, medium-severity vulnerabilities related to Markdown processing, dashboards, SSRF (server-side request forgery) risks, and less severe authorization and validation issues have been resolved.
Update Recommendations and Features
GitLab notes that all builds from previous release branches, issued before these new patches, are affected by these vulnerabilities. Typically, vulnerability details are published 30 days after a fix is released. The company emphasizes that updating to the latest supported version is essential for maintaining deployment security.
The patch release includes database migrations, which may temporarily impact availability. Single-server installations are expected to experience downtime during the update, while multi-server deployments can often update without downtime if recommended procedures are followed.
Update Frequency and Administrator Advice
GitLab follows a twice-monthly patch release schedule but may issue additional updates if critical vulnerabilities are discovered. Administrators are advised to carefully review release notes, test updates in staging environments, and deploy the latest patches as soon as possible to minimize the risk of exploitation.
