#8
The Hacker News
general
September 23, 2026 at 16:53 UTC
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
By [email protected] (The Hacker News)
AI Summary
GitLab's per-project incoming email addresses, which allow users to file issues via email, function as privileged credentials: anyone who obtains the address can commit code in the victim's name to any branch they have push access to, including main, and trigger CI/CD pipeline jobs running as that user. The addresses are accessible through the GitLab UI behind an 'Email work item to this project' button and are not rotated by default. This represents a serious supply chain and account takeover risk for any organization using GitLab's email integration feature.
Relevance score: 79.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →