Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-13874
Published: May 18, 2026
Vulnerability details
The vulnerability allows a remote user to view issues in projects they are not authorized to access.
The vulnerability exists due to improper access control in issue links API when handling issue link requests. A remote user can request linked issue data to view issues in projects they are not authorized to access.
Guest permissions are sufficient.
Affected software
GitLab Enterprise Edition
How to mitigate CVE-2025-13874
GitLab Enterprise Edition - addressed in versions 18.9.7, 18.10.6, 18.11.3