CVE-2025-6195 – Direct Request (‘Forced Browsing’) in GitLab

The following table lists the changes that have been made to the
CVE-2025-6195 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Nov. 26, 2025

    Action Type Old Value New Value
    Added Description GitLab has remediated an issue in GitLab EE affecting all versions from 13.7 before 18.4.5, 18.5 before 18.5.3, and 18.6 before 18.6.1 that could have allowed an authenticated user to view information from security reports under certain configuration conditions.
    Added CVSS V3.1 AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
    Added CWE CWE-425
    Added Reference https://gitlab.com/gitlab-org/gitlab/-/issues/549937
    Added Reference https://hackerone.com/reports/3155693
Share the Post:

Related Posts