GitLab’s non-expiring incoming email token can let a holder commit code with a user’s permissions and trigger CI/CD jobs.
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
A long-lived token embedded in GitLab’s issue-creating email address means anyone with the address, not just the project ...
How much of a software engineer's day is actually spent writing code that 'creates new value'?In many workplaces, what ...
A GitLab feature designed to let users create work items through email can be abused as an account-level code delivery ...
I want to try using Codex.But I don't have a GitHub account. Or, I feel hesitant about suddenly connecting company code to an ...
GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research published by Aikido Security researcher Joe ...
Explore the latest news, real-world incidents, expert analysis, and trends in Gitlab — only on The Hacker News, the leading ...
GitLab released emergency updates for two critical flaws enabling authenticated users to execute arbitrary code via crafted ...
"Q2 was an exceptional quarter" with "Revenue" of "$286.3 million, up 21% year-over-year," and "non-GAAP operating income" of "$42.6 million, representing a 15% operating margin" (CEO William Staples) ...
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure.
Some results have been hidden because they may be inaccessible to you
Show inaccessible results