Back to Database
Status published
High
CVE-2025-8279
Missing Authentication for Critical Function in GitLab Language Server
Vulnerability Description
Insufficient input validation within GitLab Language Server 7.6.0 and later before 7.30.0 allows arbitrary GraphQL query execution
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-8279
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- This vulnerability has been discovered internally by GitLab team member Joern Schneeweisz.
More from GitLab
View All →CVE-2025-9958
Insertion of Sensitive Information Into Sent Data in GitLab
High
7.7
CVE-2025-9957
Incorrect Authorization in GitLab
Low
2.7
CVE-2025-9825
Missing Authorization in GitLab
Medium
5
CVE-2025-9642
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
High
8.7
CVE-2025-9484
Missing Authorization in GitLab
Medium
4.3
Affected Vendor
GitLab
View all reports →Affected Software
GitLab Language Server
Vulnerable Versions:
7.6.0
Timeline
Official Publish:
July 28th, 2025
Last Modified:
July 28th, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N