VDB

CVE-2025-9825

CVE-2025-9825 PUBLISHED

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.

EPSS 0.01% · 0.9th percentile

Risk Scores

EPSS Score
0.01%
0.9th percentile

Affected Products

VendorProductVersions
Bitnamigitlab13.7.0, 18.3.0, 18.4.0
Bitnamigitlab18.3.0, 13.7.0, 18.4.0

Timeline

  • Oct 9, 2025 CVE Published
  • Nov 21, 2025 EPSS Score
  • Nov 26, 2025 EPSS Score
  • Dec 1, 2025 EPSS Score
  • Dec 5, 2025 EPSS Score
  • Dec 10, 2025 EPSS Score
  • Dec 15, 2025 EPSS Score
  • Dec 20, 2025 EPSS Score
  • Dec 25, 2025 EPSS Score
  • Dec 29, 2025 EPSS Score
  • Jan 3, 2026 EPSS Score
  • Jan 8, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›