Thehackernews GitLab Email Token Vulnerability Allows Unauthorized Code Pushes
Article Content
- •GitLab's email issue creation feature exposes a universal token if leaked.
- •Unauthorized users can push code and run CI/CD jobs using the leaked email address.
- •GitLab does not verify the sender of the email, increasing the risk of exploitation.
GitLab's private email addresses for issue creation contain a long-lived token that can be exploited if leaked. This token allows anyone with the address to push code, execute CI/CD jobs, and bypass IP restrictions across all projects the account can access. The email address appears project-specific but uses a universal token tied to the user's account. GitLab does not verify the sender of the email, meaning any mailbox can send to this address, acting as the user. Aikido Security demonstrated that even with IP restrictions in place, the email method bypassed these protections. The vulnerability affects both public and private projects, and the risk escalates based on the user's role within GitLab. GitLab has acknowledged the issue and is considering implementing sender verification. The situation remains critical as the exploit can lead to unauthorized code changes and CI/CD job executions.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Aikido Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in F5 BIG-IP APM Exploited for Remote Code Execution F5 Networks has reported a critical vulnerability in its BIG-IP Access Policy Manager (APM), tracked as CVE-2026-94127, which is being actively exploited in the wild. The flaw allows unauthenticated attackers to execute remote code on systems configured with both an APM access policy and an OAuth profile. This…
Massive Network of AI Proxy Servers Used for Malicious Activities Uncovered Security researchers from Team Cymru have identified over 10,000 proxy servers in China facilitating malicious AI activities. These servers, termed 'transfer stations,' are primarily used to bypass geographic restrictions and conduct model distillation attacks against frontier AI models. The infrastructure allows…