VDB

CVE-2025-0186

CVE-2025-0186 PUBLISHED CVSS 6.5 MEDIUM

CVE-2026-4922 is a cross-site request forgery vulnerability affecting the GraphQL API. Insufficient CSRF protection in GitLab GraphQL API allows unauthenticated users to execute GraphQL mutations on behalf of authenticated users. An attacker can craft malicious requests that, when clicked by an authenticated GitLab user, execute GraphQL mutations without the user's knowledge or consent. This could result in unauthorised modification of data and configurations within GitLab, including potential changes to project settings, user permissions, issue management, and other critical GitLab functionality. CVE-2026-5816 is an improper resolution of path equivalence flaw affecting Web IDE assets. An unauthenticated user could exploit it to execute arbitrary JavaScript in a user’s browser session. This could lead to session hijacking, credential theft, unauthorised actions performed on behalf of the user, and potential access to sensitive data. CVE-2026-5262 is a cross-site scripting vulnerability affecting Storybook. Under certain conditions, an unauthenticated attacker could exploit this vulnerability to gain unauthorised access to sensitive tokens stored in the Storybook development environment. This could lead to the compromise of authentication credentials, allowing attackers to authenticate as legitimate users and perform actions on the GitLab instance.

EPSS 0.05% · 14.6th percentile

Risk Scores

CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
0.05%
14.6th percentile

Affected Products

VendorProductVersions
GitLabGitLab Enterprise Edition
GitLabGitLab Community Edition

Timeline

  • Apr 22, 2026 CVE Published
  • Apr 22, 2026 PoC Published
  • Apr 23, 2026 Security Advisory
  • May 18, 2026 EPSS Score
  • May 19, 2026 EPSS Score
  • May 20, 2026 EPSS Score
  • May 21, 2026 EPSS Score
  • May 22, 2026 EPSS Score
  • May 23, 2026 EPSS Score
  • May 24, 2026 EPSS Score
  • May 25, 2026 EPSS Score
  • May 26, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›