Home / Jul 26, 2026 / Story
0
#3 The Hacker News general July 25, 2026 at 08:34 UTC

Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

By [email protected] (The Hacker News)

AI Summary

Security researcher Yuhang Wu published a working RCE proof-of-concept for GitLab 18.11.3 self-managed instances that allows any authenticated user — with no admin or CI runner privileges — to execute commands as the git system user. The exploit is triggered by committing two specially crafted Jupyter notebooks and requesting their diff, requiring no victim interaction beyond standard authentication. Organizations running unpatched self-managed GitLab instances should treat this as critical given the low privilege bar and publicly available exploit code.

Relevance score: 85.0/100

# More from July 26