GitLab released security updates 18.8.4, 18.7.4, and 18.6.6 for Community Edition and Enterprise Edition to fix multiple vulnerabilities affecting self-managed deployments, and urged customers to upgrade immediately. The most severe issue, CVE-2025-7659 with CVSS 8.0, is an incomplete validation flaw in the Web IDE that could allow an unauthenticated attacker to steal tokens and gain access to private repositories. GitLab.com had already been patched, and GitLab Dedicated customers were not required to take action.
The release also addressed additional vulnerabilities tracked as CVE-2025-8099, CVE-2026-0958, CVE-2026-0595, and CVE-2025-14560, covering several denial-of-service conditions, cross-site scripting, HTML injection, server-side request forgery, and authorization bypasses across GitLab CE/EE and EE. GitLab said the patch release includes database migrations that may cause downtime on single-node deployments, while multi-node environments can avoid downtime by following zero-downtime upgrade procedures.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
In the patch release details, GitLab identified CVE-2025-7659 as the most severe vulnerability addressed, describing it as a Web IDE incomplete validation flaw that could allow an unauthenticated attacker to steal tokens and access private repositories. The issue was rated high severity with a CVSS score of 8.0.
GitLab released security patch versions 18.8.4, 18.7.4, and 18.6.6 for GitLab Community Edition and Enterprise Edition, fixing multiple vulnerabilities and urging self-managed customers to upgrade immediately. GitLab.com was already patched, and GitLab Dedicated customers did not need to take action.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourcecve.org
Open sourcecve.org
Open sourcecve.org
Open sourcedocs.gitlab.com
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.