CVE-2025-4976
MEDIUMDescription
An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.
Is your site exposed to CVE-2025-4976?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| gitlab | gitlab |
| gitlab | gitlab |
| gitlab | gitlab |
References
Frequently Asked Questions
What is CVE-2025-4976? +
How severe is CVE-2025-4976? +
What products are affected by CVE-2025-4976? +
How do I check if I'm vulnerable to CVE-2025-4976? +
Related Vulnerabilities
Exposure of Sensitive Information Due to Incompatible Policies vulnerability in Mia Technology Inc. MİA-MED allows Collect Data as Provided by …
An issue has been discovered in GitLab EE/CE affecting all versions starting from 8.0 before 16.4. The product did not …
Apache Airflow 3 introduced a change to the handling of sensitive information in Connections. The intent was to restrict access …
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality …
Exposure of Sensitive Information vulnerability in Naukowa i Akademicka Sieć Komputerowa - Państwowy Instytut Badawczy EZD RP allows logged-in user …
The Dario Health Internet-based server infrastructure is vulnerable due to exposure of development environment details, which could lead to unsafe …