
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-9825 is a missing authorization vulnerability in GitLab CE/EE that allows authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API. It affects all GitLab CE/EE versions from 13.7 through 18.2.8, 18.3.0 before 18.3.4, and 18.4.0 before 18.4.2. The vulnerability was reported via HackerOne by researcher 'joaxcar' and patched on October 8, 2025. It carries a CVSS v3.1 base score of 5.0 (Medium) per the vendor advisory, though NVD rates it 6.5 (Medium) (GitLab Advisory, Red Hat CVE).
The root cause is CWE-862 (Missing Authorization): the GitLab GraphQL API endpoint for manual CI/CD job variables fails to enforce project membership checks before returning sensitive variable data. An authenticated user — regardless of project membership — can craft a GraphQL query targeting manual job variables and receive confidential CI/CD configuration values that should be restricted to project members. No elevated privileges beyond a valid GitLab account are required, and the attack is conducted entirely over the network with no user interaction (GitLab Advisory, GitLab Issue).
Successful exploitation allows an authenticated but unauthorized user to read sensitive manual CI/CD variables, which may include API keys, deployment credentials, secrets, and other confidential configuration data stored in GitLab pipelines. This constitutes a high-confidentiality impact with no integrity or availability impact. Exposed credentials could enable lateral movement into downstream infrastructure, cloud environments, or third-party services connected to the affected CI/CD pipelines (GitLab Advisory, Red Hat CVE).
A proof-of-concept reference exists in the GitLab issue tracker, though the issue was made public 30 days after the patch release per GitLab's disclosure policy. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0.000120), indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitLab Issue, Feedly).
POST /api/graphql) querying manual job variables for the target project, bypassing the missing authorization check./api/graphql from authenticated users who are not members of the queried project, particularly querying CI/CD job variable fields.POST /api/graphql from unexpected user accounts or IP addresses.GitLab has released patched versions 18.2.8, 18.3.4, and 18.4.2 on October 8, 2025, which resolve this vulnerability. All self-managed GitLab installations should upgrade to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As an interim measure, administrators should audit CI/CD variables for sensitive secrets and consider rotating any credentials that may have been exposed (GitLab Advisory).
Security news outlets including SecurityOnline.info and CyberSecurityNews covered the patch release, noting the GraphQL authorization issues addressed in the 18.4.2/18.3.4/18.2.8 update. The vulnerability was reported through GitLab's HackerOne bug bounty program by researcher 'joaxcar', reflecting the effectiveness of coordinated disclosure. Coverage was moderate, with the higher-severity CVE-2025-11340 (CVSS 7.7) in the same patch release receiving more attention (SecurityOnline, GitLab Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."