CVE-2025-3396
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-3396 is an incorrect authorization vulnerability in GitLab Enterprise Edition (EE) that allows authenticated project owners to bypass group-level forking restrictions by manipulating API requests. It affects all GitLab EE versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2. The vulnerability was disclosed on July 10, 2025, and assigned a CVSS v3.1 base score of 4.3 (Medium) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is classified as CWE-863 (Incorrect Authorization), where the application fails to properly enforce group-level forking policy controls when processing certain API requests. An authenticated project owner can craft or manipulate API requests to circumvent restrictions that a group administrator has configured to prevent repository forking. Exploitation requires only a low-privilege authenticated account (project owner role) with no user interaction, and is reachable over the network with low attack complexity. The vulnerability was originally reported via HackerOne (report #3079956) and tracked in GitLab's internal issue tracker (GitLab Issue, ZeroPath Analysis).

Impact

Successful exploitation allows a project owner to fork a repository even when group-level forking restrictions have been explicitly configured to prevent this action, resulting in a confidentiality impact (low) by potentially exposing repository contents to unauthorized destinations. While integrity and availability are not directly affected, the bypass undermines organizational governance controls — particularly in environments where forking restrictions are used to prevent sensitive code from being copied outside approved groups. The scope is limited to the affected GitLab EE instance and does not enable lateral movement or remote code execution (Red Hat CVE, Security Online).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.011% (0.000110), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Detection coverage exists via Nessus and Qualys scanners (Feedly Intelligence).

Exploitation steps

  1. Authentication: Log in to a GitLab EE instance as a user with project owner privileges within a group that has forking restrictions enabled by the group administrator.
  2. Identify restriction: Confirm that the group-level setting prohibits forking (e.g., via the group's Settings > General > Permissions page).
  3. Craft API request: Instead of using the standard GitLab web UI fork workflow (which enforces the restriction), directly call the GitLab REST API fork endpoint (e.g., POST /api/v4/projects/:id/fork) with a manipulated or crafted request that bypasses the server-side authorization check.
  4. Bypass enforcement: The server fails to correctly validate the group forking policy for the API path, allowing the fork operation to complete successfully despite the restriction.
  5. Access forked repository: The attacker now has a copy of the restricted repository in their own namespace or another group, potentially exposing sensitive source code (ZeroPath Analysis, GitLab Issue).

Indicators of compromise

  • Logs: GitLab application logs (production.log) showing successful POST /api/v4/projects/:id/fork API calls originating from project owners in groups where forking is restricted.
  • Audit Events: GitLab audit log entries recording unexpected fork operations by users in groups with forking disabled — reviewable via Admin Area > Monitoring > Audit Events.
  • Repository Activity: Unexpected new repositories appearing in user namespaces or groups that are forks of repositories from restricted groups.
  • Network: API requests to /api/v4/projects/*/fork endpoints from authenticated sessions that should not have forking permissions based on group policy configuration.

Mitigation and workarounds

GitLab has released patched versions addressing this vulnerability: 17.11.6, 18.0.4, and 18.1.2. All GitLab EE administrators running versions from 13.3 onward should upgrade to one of these fixed releases immediately. No specific configuration-based workaround has been published; upgrading is the recommended remediation. Administrators can also audit their GitLab audit logs for unexpected fork operations as a detective control while planning upgrades (GitLab Patch Release).

Community reactions

The vulnerability was covered by several security news outlets including Security Online, GBHackers, CyberPress, and CyberSecurityNews shortly after disclosure on July 10, 2025, as part of broader coverage of GitLab's patch release addressing multiple issues. Community discussion on Mastodon (infosec.exchange) noted the patch release. No major vendor statements beyond GitLab's own advisory or notable independent researcher commentary have been identified (Security Online, GBHackers).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19478CRITICAL9.4
  • GitLab logoGitLab
  • gitlab-rails-19.1
NoYesAug 17, 2026
CVE-2026-10053HIGH8.5
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 23, 2026
CVE-2026-19650HIGH7.1
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab
NoYesAug 17, 2026
CVE-2026-6821MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026
CVE-2026-4879MEDIUM4.3
  • GitLab logoGitLab
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management