Skip to finding
important · Privilege — GitLab

One leaked GitLab incoming-issue email address can become account-wide repository write and CI execution.

Affects

GitLab.com and GitLab self-managed installations with incoming email enabled; GitLab is a source-code hosting and CI/CD platform.

The embedded token acts across projects as the victim account, the mail path does not verify the sender, and changing the suffix to merge-request permits a Git patch and branch name to be submitted.

Detail and 4 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 26, 2026