{"id":"CVE-2025-9825","summary":"Missing Authorization in GitLab","details":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 to 18.2.8, 18.3 before 18.3.4, and 18.4 before 18.4.2 that could have allowed authenticated users without project membership to view sensitive manual CI/CD variables by querying the GraphQL API.","aliases":["BIT-gitlab-2025-9825"],"modified":"2026-04-02T13:19:56.152407Z","published":"2025-11-21T05:33:31.558Z","related":["CGA-6qc5-v98g-84rq"],"database_specific":{"cna_assigner":"GitLab","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9825.json","cwe_ids":["CWE-862"]},"references":[{"type":"WEB","url":"https://about.gitlab.com/releases/2025/10/08/patch-release-gitlab-18-4-2-released/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/9xxx/CVE-2025-9825.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-9825"},{"type":"REPORT","url":"https://gitlab.com/gitlab-org/gitlab/-/issues/567301"},{"type":"REPORT","url":"https://hackerone.com/reports/3319800"},{"type":"PACKAGE","url":"git://git@gitlab.com:gitlab-org/gitlab.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"036576a25d67513637c1e2cba5859af47695188e"},{"fixed":"064b7e40da0b30ea250d4486cc3f08c5328a4165"}],"database_specific":{"versions":[{"introduced":"13.7"},{"fixed":"18.2.8"}]}},{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"94282cd9b41643ecd8a82da6cf46834cd9609afe"},{"fixed":"5f66dfbe719f204a376af73ef283481886cf08d2"}],"database_specific":{"versions":[{"introduced":"18.3"},{"fixed":"18.3.4"}]}},{"type":"GIT","repo":"https://gitlab.com/gitlab-org/gitlab","events":[{"introduced":"9255f56b45844196bb7657a9f1fde6aa65a5d08d"},{"fixed":"527e88bdddb02340974a968de1ddcfa4ed7735e5"}],"database_specific":{"versions":[{"introduced":"18.4"},{"fixed":"18.4.2"}]}}],"versions":["v13.7.0-ee","v13.7.1-ee","v13.7.2-ee","v13.7.3-ee","v13.7.4-ee","v13.7.5-ee","v13.7.6-ee","v13.7.7-ee","v13.7.8-ee","v13.7.9-ee","v18.3.0-ee","v18.3.1-ee","v18.3.2-ee","v18.3.3-ee","v18.4.0-ee","v18.4.1-ee"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-9825.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N"}]}