CVE-2025-9486
An attacker can exploit multiple vulnerabilities in GitLab to perform cross-site scripting attacks, bypass security measures, escalate privileges, disclose confidential information, manipulate data, or cause a denial of service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in GitLab allow attackers to perform cross-site scripting, bypass security measures, escalate privileges, disclose information, manipulate data, or cause denial of service.
- Who is affected
- GitLab deployments are affected; specific versions not stated.
- Urgency
- High severity requires prompt patching; currently not exploited but multiple attack vectors present.
- Action
- Update GitLab to patched version addressing CVE-2025-9486, CVE-2026-15216, CVE-2026-15217, CVE-2026-15423, CVE-2026-16494, CVE-2026-16627, CVE-2026-18244, and CVE-2026-18433.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-9486
Get an email if CVE-2025-9486 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all EPSS-scored CVEs.
Advisory coverage (6)
- unknownNCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Editionncsc-nl · 2026-08-13
- high[NEW] [high] GitLab: Multiple vulnerabilitiescert-bund · 2026-08-13
- unknownMultiple vulnerabilities in GitLab (August 13, 2026)cert-fr-avis · 2026-08-13
- lowCVE-2025-9486: GitLab has remediated an issue in GitLab EE affecting all versions from 15.6 before 19.0.6, 19.…nvd · 2026-08-12
- criticalGitLab Patch Release: 19.2.2, 19.1.4, 19.0.6gitlab · 2026-08-12
- criticalGitLab Patch Release: 19.2.2, 19.1.4, 19.0.6gitlab · 2026-08-12
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-9486)