
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-3396 is an incorrect authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated project owners to bypass group-level forking restrictions by manipulating API requests. It affects all GitLab EE versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2. The vulnerability was disclosed on July 10, 2025, and assigned a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is classified as CWE-863 (Incorrect Authorization), where the application fails to properly enforce group-level forking policy controls when processing certain API requests. An authenticated project owner can craft or manipulate API requests to circumvent restrictions that a group administrator has configured to prevent repository forking. Exploitation requires only a low-privilege authenticated account (project owner role) with no user interaction, and is reachable over the network with low attack complexity. The vulnerability was originally reported via HackerOne (report #3079956) and tracked in GitLab's internal issue tracker (GitLab Issue, ZeroPath Analysis).
Successful exploitation allows a project owner to fork a repository even when group-level forking restrictions have been explicitly configured to prevent this action, resulting in a confidentiality impact (low) by potentially exposing repository contents to unauthorized destinations. While integrity and availability are not directly affected, the bypass undermines organizational governance controls — particularly in environments where forking restrictions are used to prevent sensitive code from being copied outside approved groups. The scope is limited to the affected GitLab EE instance and does not enable lateral movement or remote code execution (Red Hat CVE, Security Online).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus and Qualys scanners (Feedly Intelligence).
POST /api/v4/projects/:id/fork) with a manipulated or crafted request that bypasses the server-side authorization check.production.log) showing successful POST /api/v4/projects/:id/fork API calls originating from project owners in groups where forking is restricted./api/v4/projects/*/fork endpoints from authenticated sessions that should not have forking permissions based on group policy configuration.GitLab has released patched versions addressing this vulnerability: 17.11.6, 18.0.4, and 18.1.2. All GitLab EE administrators running versions from 13.3 onward should upgrade to one of these fixed releases immediately. No specific configuration-based workaround has been published; upgrading is the recommended remediation. Administrators can also audit their GitLab audit logs for unexpected fork operations as a detective control while planning upgrades (GitLab Patch Release).
The vulnerability was covered by several security news outlets including Security Online, GBHackers, CyberPress, and CyberSecurityNews shortly after disclosure on July 10, 2025, as part of broader coverage of GitLab's patch release addressing multiple issues. Community discussion on Mastodon (infosec.exchange) noted the patch release. No major vendor statements beyond GitLab's own advisory or notable independent researcher commentary have been identified (Security Online, GBHackers).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."