The record
Written from the 1 report below. Nothing here is unsourced.
- GitLab users have a personal email address for filing issues that contains an unexpiring security token.
- Attackers who obtain this address can send specially crafted emails to commit code and trigger CI/CD pipelines as the account owner.
- The exploit bypasses IP allowlists and two-factor authentication because incoming emails are processed differently.
- GitLab currently treats the address as a standard credential and does not allow users to disable the feature.
What to watch next
- Future implementation of email sender verification on GitLab accounts
- Potential changes to allow individual users to disable email-based issue creation
- GitLab's response to security community pressure regarding the token's non-expiring nature
Coverage1
1 report
English national1
All filed from India
Named United States · GitLab · Aikido Security · HackerOne
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
