CVE-2025-9825
GitLab vulnerability analysis and mitigation

Overview

CVE-2025-9825 is a missing authorization vulnerability in GitLab CE/EE that allows authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API. It affects all GitLab CE/EE versions from 13.7 through 18.2.8, 18.3.0 before 18.3.4, and 18.4.0 before 18.4.2. The vulnerability was reported via HackerOne by researcher 'joaxcar' and patched on October 8, 2025. It carries a CVSS v3.1 base score of 5.0 (Medium) per the vendor advisory, though NVD rates it 6.5 (Medium) (GitLab Advisory, Red Hat CVE).

Technical details

The root cause is CWE-862 (Missing Authorization): the GitLab GraphQL API endpoint for manual CI/CD job variables fails to enforce project membership checks before returning sensitive variable data. An authenticated user — regardless of project membership — can craft a GraphQL query targeting manual job variables and receive confidential CI/CD configuration values that should be restricted to project members. No elevated privileges beyond a valid GitLab account are required, and the attack is conducted entirely over the network with no user interaction (GitLab Advisory, GitLab Issue).

Impact

Successful exploitation allows an authenticated but unauthorized user to read sensitive manual CI/CD variables, which may include API keys, deployment credentials, secrets, and other confidential configuration data stored in GitLab pipelines. This constitutes a high-confidentiality impact with no integrity or availability impact. Exposed credentials could enable lateral movement into downstream infrastructure, cloud environments, or third-party services connected to the affected CI/CD pipelines (GitLab Advisory, Red Hat CVE).

Exploitability

A proof-of-concept reference exists in the GitLab issue tracker, though the issue was made public 30 days after the patch release per GitLab's disclosure policy. There is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.012% (0.000120), indicating low current exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitLab Issue, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a GitLab CE/EE instance running a vulnerable version (13.7–18.2.8, 18.3.0–18.3.3, or 18.4.0–18.4.1) using version disclosure endpoints or banner information.
  2. Authenticate: Obtain any valid GitLab account on the target instance — no project membership or elevated privileges are required.
  3. Identify target project: Enumerate accessible projects or identify a specific project whose CI/CD variables are of interest.
  4. Craft GraphQL query: Send a GraphQL API request (e.g., POST /api/graphql) querying manual job variables for the target project, bypassing the missing authorization check.
  5. Retrieve sensitive variables: Parse the API response to extract manual CI/CD variable names and values, which may include secrets, tokens, or deployment credentials (GitLab Advisory, GitLab Issue).

Indicators of compromise

  • Network: Unusual or repeated GraphQL API POST requests to /api/graphql from authenticated users who are not members of the queried project, particularly querying CI/CD job variable fields.
  • Logs: GitLab application logs showing GraphQL queries for manual job variables from accounts with no project membership; access log entries with POST /api/graphql from unexpected user accounts or IP addresses.
  • Behavioral: A single user account querying CI/CD variable data across multiple projects they are not members of in a short time window.

Mitigation and workarounds

GitLab has released patched versions 18.2.8, 18.3.4, and 18.4.2 on October 8, 2025, which resolve this vulnerability. All self-managed GitLab installations should upgrade to one of these versions immediately. GitLab.com is already running the patched version, and GitLab Dedicated customers do not need to take action. As an interim measure, administrators should audit CI/CD variables for sensitive secrets and consider rotating any credentials that may have been exposed (GitLab Advisory).

Community reactions

Security news outlets including SecurityOnline.info and CyberSecurityNews covered the patch release, noting the GraphQL authorization issues addressed in the 18.4.2/18.3.4/18.2.8 update. The vulnerability was reported through GitLab's HackerOne bug bounty program by researcher 'joaxcar', reflecting the effectiveness of coordinated disclosure. Coverage was moderate, with the higher-severity CVE-2025-11340 (CVSS 7.7) in the same patch release receiving more attention (SecurityOnline, GitLab Advisory).

Additional resources


SourceThis report was generated using AI

Related GitLab vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16553MEDIUM5.4
  • GitLab logoGitLab
  • gitlab
NoYesJul 29, 2026
CVE-2026-6336MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-workhorse-ce-18.8
NoYesJul 29, 2026
CVE-2026-6267MEDIUM5.3
  • GitLab logoGitLab
  • gitlab-rails-ce-18.7
NoYesJul 29, 2026
CVE-2026-3093MEDIUM4.7
  • GitLab logoGitLab
  • gitlab-rails-ce-fips-18.6
NoYesJul 29, 2026
CVE-2026-4672MEDIUM4.3
  • GitLab logoGitLab
  • gitlab-rails-ce-18.6
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management