CVE advisoryCRITICAL
CVE-2025-13761
GitLab Unauthenticated Code Execution via Crafted Webpage in Browser
Halo Surface Signal: 4 out of 5 — likely to be public-facing.
A critical vulnerability in GitLab allows unauthenticated users to execute arbitrary code in a user's browser if that user visits a specially crafted webpage. This could impact the confidentiality, integrity, and availability of the system.