{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-01T19:43:38.451","vulnerabilities":[{"cve":{"id":"CVE-2025-4976","sourceIdentifier":"cve@gitlab.com","published":"2025-07-24T07:15:53.963","lastModified":"2026-06-17T09:34:25.403","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses."},{"lang":"es","value":"Se ha descubierto un problema en GitLab EE que afecta a todas las versiones desde la 17.0 hasta la 18.0.5, la 18.1 hasta la 18.1.3 y la 18.2 hasta la 18.2.1 que, en determinadas circunstancias, podría haber permitido a un atacante acceder a notas internas en las respuestas de GitLab Duo."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"17.0","lessThan":"18.0.5","versionType":"semver","status":"affected"},{"version":"18.1","lessThan":"18.1.3","versionType":"semver","status":"affected"},{"version":"18.2","lessThan":"18.2.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","baseScore":4.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":1.4},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-07-24T13:10:43.770952Z","id":"CVE-2025-4976","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-213"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.0.0","versionEndExcluding":"18.0.5","matchCriteriaId":"3A900441-295E-449E-8CF9-E6CF7BBF6A2E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"18.1.0","versionEndExcluding":"18.1.3","matchCriteriaId":"1BD9DE80-2A4C-421F-98AC-25F160771956"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*","matchCriteriaId":"8931BAA0-5961-46EC-BF0C-62EE4E8A7BE1"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/543905","source":"cve@gitlab.com","tags":["Broken Link"]},{"url":"https://hackerone.com/reports/3149956","source":"cve@gitlab.com","tags":["Permissions Required"]}]}}]}