< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-25T15:44:26+05:30

GitLab RCE PoC Exploit Allows Authenticated Users to Execute Commands as Git

A researcher published a proof-of-concept exploit (PoC) for a GitLab remote code execution (RCE) vulnerability affecting self-managed instances, allowing authenticated users to execute commands as the 'git' user through a Jupyter notebook-based attack chain. The flaw, tied to memory corruption in the Oj gem, was patched in June 2026 but remains unclassified as a security issue with no CVE or CVSS score.

Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Any authenticated user who can push to a project can run it. The attacker commits a crafted Jupyter notebook and opens its commit diff, which leaks a heap

Read original article

*** END OF TRANSMISSION ***