Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flavored Markdown.

INFO

Published Date :

2026-01-09T10:04:36.272Z

Last Modified :

2026-01-10T04:55:47.964Z

Source :

GitLab
AFFECTED PRODUCTS

The following products are affected by CVE-2025-9222 vulnerability.

Vendors Products
Gitlab
  • Gitlab

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact