GitLab released emergency updates for GitLab CE and EE to fix nine vulnerabilities, including two critical authentication flaws in the third-party ruby-saml library that can let an attacker impersonate arbitrary users in SAML SSO deployments. The issues, tracked as CVE-2025-25291 and CVE-2025-25292, stem from SAML parser differential behavior that can enable a valid SAML-signing party to bypass authentication checks and effectively sign in as another user. GitHub security researchers disclosed the underlying SAML weakness, describing how parser inconsistencies can break trust assumptions in SSO authentication flows.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On March 19, 2025, CSIRT.SK published an advisory highlighting that the patched GitLab vulnerabilities could be exploited for arbitrary user impersonation via SAML SSO and remote code execution via the Direct Transfer feature. The notice urged immediate upgrades and listed mitigations such as enforcing 2FA, disabling SAML 2FA bypass, requiring admin approval for new users, and disabling Direct Transfer.
On March 12, 2025, GitLab released versions 17.9.2, 17.8.5, and 17.7.7 for CE and EE to fix multiple security issues. The release addressed critical ruby-saml flaws CVE-2025-25291 and CVE-2025-25292, as well as critical GraphQL remote code execution flaw CVE-2025-27407, and GitLab said GitLab.com was already patched.
GitHub security researchers reported vulnerabilities CVE-2025-25291 and CVE-2025-25292 in the third-party ruby-saml library. The flaws can allow authentication bypass and user impersonation in SAML SSO deployments due to parser differentials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcegithub.blog
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.