important · Privilege — GitLab
One leaked GitLab incoming-issue email address can become account-wide repository write and CI execution.
Affects
GitLab.com and GitLab self-managed installations with incoming email enabled; GitLab is a source-code hosting and CI/CD platform.
The embedded token acts across projects as the victim account, the mail path does not verify the sender, and changing the suffix to merge-request permits a Git patch and branch name to be submitted.
Detail and 4 sources
The researcher demonstrated a push to main and CI execution in an IP-allowlisted private project; GitLab's documentation and interface changes did not remove the underlying authority.
Sources
ResearchSende eine E-Mail an GitLab, führe einen Push in den Hauptzweig durchCode / PoCAlign incoming email token capability across UI and docs (!247431) · Merge requests · GitLab.org / GitLab · GitLabCode / PoCEmail verification for incoming email token actions (#617883) · Issues · GitLab.org / GitLab · GitLabCode / PoCGitHub - betterleaks/betterleaks: Find leaked secrets everywhere. · GitHub