VDB
CVE-2025-9825
CVE-2025-9825
PUBLISHED
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.
EPSS 0.01% · 0.9th percentile
Risk Scores
EPSS Score
0.01%
0.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 13.7.0, 18.3.0, 18.4.0 |
| Bitnami | gitlab | 18.3.0, 13.7.0, 18.4.0 |
Timeline
- Oct 9, 2025 CVE Published
- Nov 21, 2025 EPSS Score
- Nov 26, 2025 EPSS Score
- Dec 1, 2025 EPSS Score
- Dec 5, 2025 EPSS Score
- Dec 10, 2025 EPSS Score
- Dec 15, 2025 EPSS Score
- Dec 20, 2025 EPSS Score
- Dec 25, 2025 EPSS Score
- Dec 29, 2025 EPSS Score
- Jan 3, 2026 EPSS Score
- Jan 8, 2026 EPSS Score