All verified exploits

CVE-2025-7659 Web IDE Origin Validation Bypass

Deterministic high GitLab Added cve-verified-cve-2025-7659

Detects GitLab instances where the Web IDE iframe accepts arbitrary parentOrigin parameters, allowing cross-origin token theft. Versions 18.2.0–18.6.5, 18.7.0–18.7.3, and 18.8.0–18.8.3 are affected.

Is your app exploitable through CVE-2025-7659?

Scan your domain free