Skip to content
GitLab Email Token Vulnerability Allows Unauthorized Code Pushes

GitLab Email Token Vulnerability Allows Unauthorized Code Pushes

First seen 24 Sep 2026, 16:02 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 24, 2026 at 20:52 UTC
  • •GitLab's email issue creation feature exposes a universal token if leaked.
  • •Unauthorized users can push code and run CI/CD jobs using the leaked email address.
  • •GitLab does not verify the sender of the email, increasing the risk of exploitation.

GitLab's private email addresses for issue creation contain a long-lived token that can be exploited if leaked. This token allows anyone with the address to push code, execute CI/CD jobs, and bypass IP restrictions across all projects the account can access. The email address appears project-specific but uses a universal token tied to the user's account. GitLab does not verify the sender of the email, meaning any mailbox can send to this address, acting as the user. Aikido Security demonstrated that even with IP restrictions in place, the email method bypassed these protections. The vulnerability affects both public and private projects, and the risk escalates based on the user's role within GitLab. GitLab has acknowledged the issue and is considering implementing sender verification. The situation remains critical as the exploit can lead to unauthorized code changes and CI/CD job executions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-23
Aikido Security reports GitLab email vulnerability
Aikido Security disclosed that GitLab's email addresses for issue creation allow unauthorized code pushes due to a shared token.
Aikido.Dev
2026-09-24
The Hacker News covers GitLab vulnerability
The Hacker News reported on the implications of the leaked GitLab email addresses, detailing how they can be exploited.
Thehackernews

More articles in this cluster (2)

Following this threat?

Track Aikido Security in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed