CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-12506

criticalCVSS 3.5covered by 6 sourcesfirst seen 2026-07-08
A remote, authenticated attacker can exploit multiple vulnerabilities in GitLab to execute arbitrary code, perform Cross-Site Scripting, manipulate data, or disclose confidential information.

CSIRTS triage

What
Multiple vulnerabilities in GitLab can lead to arbitrary code execution, XSS, data manipulation, and information disclosure.
Who is affected
Deployments of GitLab are affected by these vulnerabilities.
Urgency
Remediation is urgent due to the high severity and potential for exploitation.
Action
Update to the latest version of GitLab to mitigate these vulnerabilities.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-12506

Get an email if CVE-2025-12506 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (6)

External references

NVD record for CVE-2025-12506

CVE.org record

Embed the live status

CVE-2025-12506 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-12506 status](https://www.csirts.com/badge/CVE-2025-12506)](https://www.csirts.com/cve/CVE-2025-12506)