Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Vulnerability Exposes Private Repositories to Code Injections

GitLab Vulnerability Exposes Private Repositories to Code Injections

Posted on September 23, 2026 By CWS

An investigation by Aikido Security’s researcher Joe Leon, published on September 23, 2026, reveals a significant vulnerability in GitLab’s ‘Email work item to this project’ feature. This flaw could potentially allow unauthorized code injection into private repositories if the assigned private address is exposed.

Understanding the Vulnerability

The crux of the issue lies in the glimt-incoming-email token associated with the feature, which GitLab confirms as non-expiring and confidential. Possession of this token enables the creation of issues and merge requests under the token owner’s name, posing a severe threat to repository security.

Aikido Security found that while the interface provides a project-specific email address, these addresses share an account-level token across different projects. This commonality allows attackers to manipulate the address suffix to exploit the system further.

Exploitation Techniques

Attackers can modify the ‘-issue’ suffix to ‘-merge-request’, attach a malicious Git patch, and specify a source branch in the email subject. Consequently, GitLab may apply this patch using the compromised user’s permissions. Such actions can alter the .gitlab-ci.yml file, enabling attacker-controlled CI/CD executions within the victim’s project.

The severity of this exploitation varies with the user’s role and pipeline settings, potentially exposing sensitive data like source code, CI/CD variables, or job tokens. In some scenarios, maintainers’ leaked addresses could permit unauthorized commits to protected branches under the victim’s identity.

Network Security Challenges

Aikido Security’s research also challenges assumptions about network controls. They demonstrated that GitLab accepts emailed patches even when other access methods are blocked by IP restrictions, indicating that incoming emails bypass such security measures.

Successful exploitation requires not only the private address but also sufficient information to target the project, such as its path and ID. While public repositories reveal these details, private projects generally require additional leaks to be vulnerable.

Preventive Measures and GitLab’s Response

GitLab has acknowledged the behavior as intentional rather than a bug, subsequently updating documentation to clarify token capabilities and emphasize the importance of maintaining secrecy. Although the email mechanism persists, the updated text highlights the necessary precautions.

Security teams are urged to examine repositories, logs, and other resources for exposure of glimt- addresses or outdated tokens. If exposure is suspected, resetting the incoming email token and reviewing user permissions and project security settings are critical steps.

Organizations must treat project email addresses with the same caution as account credentials to prevent unauthorized access and maintain repository integrity.

Cyber Security News Tags:Aikido Security, CI/CD, code injection, Cybersecurity, email feature, GitLab, network security, private repositories, repository compromise, Security, Token, Vulnerability

Post navigation

Previous Post: MikroTrick Exploit Grants Router Control Without Authentication
Next Post: New AI Models by Anthropic and OpenAI Show Progress in Safety

Related Posts

Microsoft Patched Windows Server 2025 Restart Bug Disconnects AD Domain Controller Microsoft Patched Windows Server 2025 Restart Bug Disconnects AD Domain Controller Cyber Security News
New Browser-Based Ransomware Targets Android Photos New Browser-Based Ransomware Targets Android Photos Cyber Security News
Weaver E-cology RCE Flaw Under Active Exploitation Weaver E-cology RCE Flaw Under Active Exploitation Cyber Security News
Achieving Data Privacy Regulation Compliance in 2025 Frameworks Achieving Data Privacy Regulation Compliance in 2025 Frameworks Cyber Security News
AI Safety Leadership in Flux as Director Resigns AI Safety Leadership in Flux as Director Resigns Cyber Security News
MagicAd Malware Bypasses Android Restrictions with Ads MagicAd Malware Bypasses Android Restrictions with Ads Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack
  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Konni Malware Campaign Targets Ukrainian Entities with Fake PDFs
  • Agentic Remediation: Closing the Loop in Cybersecurity
  • WordPress Security Flaw CVE-2026-87902 Under Attack
  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark