CVE-2025-55285: Template Secret leakage in logs in Scaffolder when using `fetch:template`
Duplicate logging of the input values in the fetch:template
action in the Scaffolder meant that some of the secrets were not properly redacted. If you’re not passing through ${{ secrets.x }}
to fetch:template
there is no impact.
References
Code Behaviors & Features
Detect and mitigate CVE-2025-55285 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →