Home / Sep 25, 2026 / Story
0
#8 The Hacker News general September 23, 2026 at 16:53 UTC

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

By [email protected] (The Hacker News)

AI Summary

GitLab's per-project incoming email addresses, which allow users to file issues via email, function as privileged credentials: anyone who obtains the address can commit code in the victim's name to any branch they have push access to, including main, and trigger CI/CD pipeline jobs running as that user. The addresses are accessible through the GitLab UI behind an 'Email work item to this project' button and are not rotated by default. This represents a serious supply chain and account takeover risk for any organization using GitLab's email integration feature.

Relevance score: 79.0/100

# More from September 25