CVE-2025-25291: GitLab SAML Authentication Bypass
Can GitLab SAML authentication be bypassed?
An authentication bypass in GitLab via a parser differential in ruby-saml. Attackers can craft SAML responses that bypass signature verification, allowing login as any user including administrators without valid credentials.
Impact & Exploitation
Affects GitLab instances with SAML SSO enabled. Enables complete account takeover including admin access. Source code theft, CI/CD pipeline compromise, and supply chain attacks.

Precogs Research
This vulnerability intelligence report was analyzed and enriched by the Precogs AI Security Team. Our researchers continuously monitor emerging threats across AI code, LLM pipelines, and binary architectures to ensure accurate real-time remediation guidance.