#VU111931 Missing authorization in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-1754
Published: June 25, 2025
Gitlab Community Edition
GitLab Enterprise Edition
GitLab, Inc
Description
The vulnerability allows a remote attacker to upload arbitrary files to the system.
The vulnerability exists due to missing authorization checks in the API. A remote non-authenticated attacker can upload arbitrary files to public projects by sending crafted API requests and consume all available storage, leading to a denial of service condition.