Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-13874

 

Improper access control in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2025-13874

Published: May 18, 2026


Vulnerability identifier: #VU131686
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-13874
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to view issues in projects they are not authorized to access.

The vulnerability exists due to improper access control in issue links API when handling issue link requests. A remote user can request linked issue data to view issues in projects they are not authorized to access.

Guest permissions are sufficient.


Affected software

Gitlab Community Edition
GitLab Enterprise Edition

How to mitigate CVE-2025-13874

Install security update from vendor's website.

Gitlab Community Edition - addressed in versions 18.9.7, 18.10.6, 18.11.3
GitLab Enterprise Edition - addressed in versions 18.9.7, 18.10.6, 18.11.3

External References

Related Security Bulletins