GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories

GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research published by Aikido Security researcher Joe Leon on September 23, 2026. The address contains a long-lived glimt- incoming-email token that GitLab says does not expire and must remain secret. GitLab documentation confirms that […]

This article has been indexed from Cyber Security News

Read the original article: