Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitLab Vulnerability Exposes Private Repositories to Code Injections

GitLab Vulnerability Exposes Private Repositories to Code Injections

Posted on September 23, 2026 By CWS

An investigation by Aikido Security’s researcher Joe Leon, published on September 23, 2026, reveals a significant vulnerability in GitLab’s ‘Email work item to this project’ feature. This flaw could potentially allow unauthorized code injection into private repositories if the assigned private address is exposed.

Understanding the Vulnerability

The crux of the issue lies in the glimt-incoming-email token associated with the feature, which GitLab confirms as non-expiring and confidential. Possession of this token enables the creation of issues and merge requests under the token owner’s name, posing a severe threat to repository security.

Aikido Security found that while the interface provides a project-specific email address, these addresses share an account-level token across different projects. This commonality allows attackers to manipulate the address suffix to exploit the system further.

Exploitation Techniques

Attackers can modify the ‘-issue’ suffix to ‘-merge-request’, attach a malicious Git patch, and specify a source branch in the email subject. Consequently, GitLab may apply this patch using the compromised user’s permissions. Such actions can alter the .gitlab-ci.yml file, enabling attacker-controlled CI/CD executions within the victim’s project.

The severity of this exploitation varies with the user’s role and pipeline settings, potentially exposing sensitive data like source code, CI/CD variables, or job tokens. In some scenarios, maintainers’ leaked addresses could permit unauthorized commits to protected branches under the victim’s identity.

Network Security Challenges

Aikido Security’s research also challenges assumptions about network controls. They demonstrated that GitLab accepts emailed patches even when other access methods are blocked by IP restrictions, indicating that incoming emails bypass such security measures.

Successful exploitation requires not only the private address but also sufficient information to target the project, such as its path and ID. While public repositories reveal these details, private projects generally require additional leaks to be vulnerable.

Preventive Measures and GitLab’s Response

GitLab has acknowledged the behavior as intentional rather than a bug, subsequently updating documentation to clarify token capabilities and emphasize the importance of maintaining secrecy. Although the email mechanism persists, the updated text highlights the necessary precautions.

Security teams are urged to examine repositories, logs, and other resources for exposure of glimt- addresses or outdated tokens. If exposure is suspected, resetting the incoming email token and reviewing user permissions and project security settings are critical steps.

Organizations must treat project email addresses with the same caution as account credentials to prevent unauthorized access and maintain repository integrity.

Cyber Security News Tags:Aikido Security, CI/CD, code injection, Cybersecurity, email feature, GitLab, network security, private repositories, repository compromise, Security, Token, Vulnerability

Post navigation

Previous Post: MikroTrick Exploit Grants Router Control Without Authentication
Next Post: New AI Models by Anthropic and OpenAI Show Progress in Safety

Related Posts

Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure Red Hat Openshift AI Service Vulnerability Allow Attackers to Take Control of the Infrastructure Cyber Security News
Windows 11 App Promotes Bing in Major Browsers Windows 11 App Promotes Bing in Major Browsers Cyber Security News
Tycoon 2FA Phishing Kit Exploits OAuth for Account Breaches Tycoon 2FA Phishing Kit Exploits OAuth for Account Breaches Cyber Security News
OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber OpenAI Launches Expanded Cyber Defense with GPT-5.4-Cyber Cyber Security News
Russian Nationals Charged in M Cybercrime Case Russian Nationals Charged in $62M Cybercrime Case Cyber Security News
Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware Fake Captcha Ecosystem Exploits Trusted Web Infrastructure to Deliver Malware Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security
  • AI Agents Amplify Secrets Sprawl in Software Development
  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Android Trojan Targets Banking Apps
  • AI-Driven Attacks Threaten Online Retail Security
  • AI Agents Amplify Secrets Sprawl in Software Development
  • Microsoft’s AI-Driven SOC Enhancements with SIEM Integration
  • Island Secures $400M Funding, Reaches $6.4B Valuation

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark