Cross-site scripting in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-12669
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to inject HTML and JavaScript into email notifications sent to other users.
The vulnerability exists due to improper input sanitization in achievement email notifications when generating notification content. A remote user can inject crafted HTML and JavaScript to inject HTML and JavaScript into email notifications sent to other users.
User interaction is required to open the email notification.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2025-12669
GitLab Enterprise Edition - addressed in versions 18.9.7, 18.10.6, 18.11.3