• Sign in
  • Register

Lost your password?

A password will be sent to your email address.

Your personal data will be used to support your experience throughout this website, to manage access to your account, and for other purposes described in our privacy policy.

Close
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
logo
  • Home
  • Cybersecurity
    • Risk Managemet & COMPLIANCE

      Penetration Test

      Vulnerability Assessment

      IT Documentation and Policies Audit

      Infrastructure Security

      Firewall & WAF Management

      Backup & Data Encryption

      Website Recovery

      INCIDENT RESPONSE

      Ransomware Response

      IT System Recovery

      Social Media Recovery

  • IT Services
    • Information technology services

      CCTV Monitoring and Management

      Wi-Fi Management

      Support services

      End-user management

      Microsoft 365 Management

      infrastructure services

      IT infrastructure Design and Implementation

      Cloud Migration and Management

  • Guides
    • Video Guides
    • Cybersecurity News
  • Shop
    • Solutions
    • Services
    • Hardware
  • Hospitality IT
Cyber Defense

GitLab Fixes Critical Security Flaws That Let Hackers Hijack Accounts and Inject Malicious Code

ClickControl

Author

June 16, 2025

Published


# GitLab Patches Critical Security Vulnerabilities Affecting Account Security and CI/CD Pipelines

GitLab has urgently released security updates to fix multiple critical vulnerabilities in its DevSecOps platform that could allow attackers to hijack user accounts and inject malicious code into CI/CD pipelines.

## Critical Updates Released

The company issued patches for GitLab Community and Enterprise versions 18.0.2, 17.11.4, and 17.10.8, urging all administrators to upgrade immediately. GitLab.com has already been updated, while GitLab Dedicated customers require no action.

## Key Vulnerabilities Addressed

**Account Takeover Risk (CVE-2025-4278)**
A critical HTML injection vulnerability allows remote attackers to take control of user accounts by injecting malicious code into the search page functionality.

**CI/CD Pipeline Compromise (CVE-2025-5121)**
This missing authorization flaw affects GitLab Ultimate Enterprise Edition, enabling authenticated attackers to inject malicious CI/CD jobs into any project’s future pipelines. While exploitation requires authenticated access and a GitLab Ultimate license, the potential impact is severe.

**Additional Security Fixes**
– **Cross-Site Scripting (CVE-2025-2254)**: Allows attackers to impersonate legitimate users
– **Denial of Service (CVE-2025-0673)**: Enables malicious actors to create infinite redirect loops, causing memory exhaustion

## Why This Matters

GitLab repositories are prime targets for cybercriminals due to their valuable content. Recent breaches at major organizations like Europcar Mobility Group and Pearson demonstrate the real-world impact of compromised GitLab instances.

With over 30 million registered users and adoption by more than half of Fortune 100 companies—including Goldman Sachs, Nvidia, and T-Mobile—these vulnerabilities pose significant risks to global enterprise infrastructure.

Organizations should prioritize immediate patching to protect their development pipelines and sensitive source code from potential exploitation.

Keywords: GitLab security vulnerabilities, GitLab critical patches, CI/CD pipeline security, GitLab account takeover, CVE-2025-4278, GitLab Enterprise security updates

Share This Article
Tags: CI/CD pipeline security CVE-2025-4278 GitLab account takeover GitLab critical patches GitLab Enterprise security updates GitLab security vulnerabilities
Previous Article New Ransomware Anubis Destroys Files
Next Article Ex-Black Basta Hackers Weaponize Microsoft
Curve Line
logo_white

601 Notre Dame E.
Montreal, Quebec, H2Y 0C2

Quick Links
  • Cybersecurity News
  • Video Guides
  • Shop
Company
  • Home
  • About us
  • Contact
  • Careers
  • Privacy Policy
Get In Touch

Montreal: +1-438-600-2288
Miami: +1-786-442-1805
Toll-Free: 1-877-654-9901

Linkedin Instagram Youtube

(C) Copyright 2023-2025 ClickControl IT MSP & Cybersecurity, All Rights Reserved.