Detects GitLab instances where the Web IDE iframe accepts arbitrary parentOrigin parameters, allowing cross-origin token theft. Versions 18.2.0–18.6.5, 18.7.0–18.7.3, and 18.8.0–18.8.3 are affected.
Is your app exploitable through CVE-2025-7659?
Scan your domain free