CVE-2025-12669 | GitLab Community Edition/Enterprise Edition up to 18.9.6/18.10.5/18.11.2 Email Notification code injection (EUVD-2025-209832 / Nessus ID 316466)
A vulnerability, which was classified as critical, has been found in GitLab Community Edition and Enterprise Edition up to 18.9.6/18.10.5/18.11.2. This affects an unknown part of the component Email Notification Handler. This manipulation causes code injection.
This vulnerability is registered as CVE-2025-12669. Remote exploitation of the attack is possible. No exploit is available.
It is advisable to upgrade the affected component.