negativeSYS.SOURCE: The Hacker News• 2026-09-23T22:23:10+05:30
GitLab Email Token Vulnerability Allows Unauthorized Code Pushes and CI/CD Execution
A leaked GitLab email token allows attackers to push code and execute CI/CD jobs as the user by exploiting unverified email-based issue/merge request features. GitLab confirms the token persists indefinitely and does not restrict access based on email origin or user permissions.
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.
GitLab shows each user this address behind a button labeled "Email work item to this project." Mail sent to it opens an issue in that project, authored
*** END OF TRANSMISSION ***