PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-13874 Hackerone CVE debrief

GitLab remediated an authorization flaw in GitLab CE/EE that could allow an authenticated user with Guest permissions to view issues in projects they were not authorized to access. The issue is tracked as CVE-2025-13874 and was publicly disclosed on 2026-05-14. It affects GitLab CE/EE versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3.

Vendor
Hackerone
Product
Unknown
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-14
Original CVE updated
2026-05-14
Advisory published
2026-05-14
Advisory updated
2026-05-14

Who should care

GitLab CE/EE administrators, security teams, and project owners who rely on Guest-role access controls should prioritize this advisory, especially if Guest access is enabled across many projects or sensitive issues are stored in GitLab.

Technical summary

This is an access-control bypass classified by CWE-639 (Authorization Bypass Through User-Controlled Key). The published CVSS vector is CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, indicating a network-reachable issue requiring low-privilege authenticated access and resulting in limited confidentiality impact. According to the advisory text, a Guest user could view issues in projects outside their authorization boundary.

Defensive priority

Medium. The vulnerability requires authenticated access, but it undermines project-level confidentiality and can expose issue content to users with only Guest permissions.

Recommended defensive actions

  • Upgrade GitLab CE/EE to 18.9.7, 18.10.6, or 18.11.3, depending on your release line.
  • Verify whether Guest access is enabled on any projects that contain sensitive issue data.
  • Review project membership and permission assignments for accounts with Guest roles.
  • Audit issue visibility and access controls in projects where Guest users are present.
  • Use the official GitLab release note and advisory references to confirm remediation status across your deployments.

Evidence notes

Source material consistently states that GitLab CE/EE versions from 15.1 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 were affected. The advisory describes an authenticated Guest user being able to view issues in projects they were not authorized to access. NVD lists the CVSS vector as CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N and CWE-639. Dates used here reflect the CVE/source publication timestamps provided: 2026-05-14.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-13874 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-13874

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-13874 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-13874

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://github.com/advisories/GHSA-576j-7qww-f874

    github_advisory_database

  • Source reference

    Unverified legacy reference

    URL: https://hackerone.com/reports/3445398

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://about.gitlab.com/releases/2026/05/13/patch-release-gitlab-18-11-3-released

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://gitlab.com/gitlab-org/gitlab/-/work_items/582634

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.