CVE-2025-13781
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-13781 is a Missing Authorization vulnerability in GitLab Enterprise Edition (EE) that allows any authenticated user to modify instance-wide AI feature provider settings by exploiting absent authorization checks in GraphQL mutations. It affects GitLab EE versions 18.5.0 through 18.5.4, 18.6.0 through 18.6.2, and 18.7.0. The vulnerability was reported via HackerOne by researcher "pwnie" and disclosed on January 9, 2026, with patches released on January 7, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (GitLab Advisory, NVD).

Technical details

The root cause is CWE-862 (Missing Authorization): GitLab EE's GraphQL API layer fails to enforce administrator-level privilege checks on mutations that control instance-wide AI feature provider configuration. An authenticated user with only standard (low-privilege) access can craft and submit GraphQL mutation requests targeting these AI settings endpoints without being blocked by any authorization gate. No special configuration or elevated role is required beyond a valid authenticated session, making the attack surface broad on any affected self-managed GitLab EE instance. The HackerOne report (restricted) and the GitLab issue tracker entry provide additional context (GitLab Advisory, NVD).

Impact

Successful exploitation allows any authenticated user to arbitrarily modify instance-wide AI feature provider settings — such as which AI backend or model is used across the entire GitLab instance — without administrator approval. This poses a high integrity risk: a malicious insider or compromised account could redirect AI processing to an attacker-controlled provider, potentially intercepting sensitive code, prompts, or data submitted by other users to GitLab Duo AI features. Confidentiality and availability are not directly impacted by this vulnerability, but the integrity compromise of AI provider configuration could have downstream effects on all users relying on those features (GitLab Advisory, NVD).

Exploitation steps

  1. Reconnaissance: Identify a self-managed GitLab EE instance running versions 18.5.0–18.5.4, 18.6.0–18.6.2, or 18.7.0 using version disclosure endpoints (e.g., /api/v4/version) or public GitLab instance directories.
  2. Authentication: Obtain or use any valid authenticated user account on the target instance — no elevated privileges are required.
  3. Craft malicious GraphQL mutation: Construct a GraphQL mutation request targeting the AI feature provider settings endpoint (e.g., a mutation that updates instance-level AI provider configuration), which lacks server-side authorization enforcement.
  4. Submit the request: Send the crafted GraphQL mutation via an HTTP POST to the GitLab GraphQL API endpoint (/api/graphql) using the authenticated session token.
  5. Achieve unauthorized modification: The server processes the mutation without verifying administrator privileges, applying the attacker-specified AI provider settings instance-wide, potentially redirecting AI feature traffic to an attacker-controlled backend (GitLab Advisory, NVD).

Indicators of compromise

  • Network: Unexpected GraphQL POST requests to /api/graphql from non-administrative user accounts containing AI provider configuration mutation payloads.
  • Logs: GitLab application logs (production.log) showing GraphQL mutations related to AI feature provider settings (e.g., mutations referencing aiFeatureProvider, aiSettings, or similar fields) originating from low-privilege user accounts.
  • Application: Unexpected changes to instance-level AI feature provider configuration in GitLab Admin Area → Settings → AI-powered features, particularly if not initiated by an administrator.
  • Audit Events: GitLab audit log entries recording AI provider setting changes attributed to non-admin users.

Mitigation and workarounds

GitLab released patched versions on January 7, 2026: 18.7.1, 18.6.3, and 18.5.5 for GitLab EE. All self-managed GitLab EE installations running affected versions (18.5.0–18.5.4, 18.6.0–18.6.2, or 18.7.0) should upgrade immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. No configuration-based workaround is documented; upgrading to a fixed version is the only recommended remediation (GitLab Advisory).

Community reactions

Security news outlets including SecurityOnline.info, GBHackers, and CyberPress covered the January 2026 GitLab patch release, noting the batch of fixes including this AI authorization flaw alongside higher-severity XSS vulnerabilities. Community discussion was limited given the medium severity rating. Qualys included detection for this CVE in their January 2026 application security detections update. No notable individual researcher commentary beyond the HackerOne reporter ("pwnie") has been publicly attributed (GitLab Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6267HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026
CVE-2026-16553MEDIUM5.4
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026
CVE-2026-6336MEDIUM5.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026
CVE-2026-3093MEDIUM4.7
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026
CVE-2026-4672MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management