CVE-2025-2255 | GitLab Community Edition/Enterprise Edition up to 17.8.5/17.9.2/17.10.0 Error Message cross site scripting (Issue 524635 / Nessus ID 233432)
A vulnerability was found in GitLab Community Edition and Enterprise Edition up to 17.8.5/17.9.2/17.10.0. It has been classified as problematic. Affected is an unknown function of the component Error Message Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2025-2255. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.