Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Exposed GitLab project email addresses let attackers push code

    September 24, 2026

    This ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans

    September 24, 2026

    Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

    September 24, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Exposed GitLab project email addresses let attackers push code
    News

    Exposed GitLab project email addresses let attackers push code

    adminBy adminSeptember 24, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Exposed GitLab project email addresses let attackers push code

    Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports.

    The addresses are part of a built-in GitLab feature called “Email work item to this project” and contain a long-lived token tied to the developer’s account.

    These addresses are generated automatically and contain a string that serves as a credential for creating work items via email. When an external client sends a message to one of them, GitLab parses it into a project issue or task.

    Researchers at application security company Aikido found multiple private GitLab addresses exposed in public documentation and are warning about the associated risk.

    An attacker could use them to compromise GitLab accounts in attacks that push code to protected branches of private repositories, steal source code, collect secrets from CI/CD variables, or access confidential issues.

    Each of these private GitLab address embed a ‘glimt-’ string that acts as a credential for accessing the project, which persists across all similar addresses generated for the respective project.

    “Change the -issue suffix in the email address to -merge-request, and GitLab will open a merge request,” Aikido says.

    Swap
    Modifying the email address
    Source: Aikido

    An attacker who knows that address or can retrieve it could change the ‘-issue’ suffix to ‘merge-request,’ and GitLab would accept it, opening a merge request on the project.

    “In principle, checking the sending address matches the token owner’s email would add a layer of defense, but GitLab doesn’t do this (though they are now considering it),” the researchers say.

    “Any mailbox on the internet can send to that address, and GitLab processes the message as the token’s owner.”

    Additionally, Aikido’s tests showed that the attack would bypass IP address restrictions as well.

    The resulting level of access depends on the user’s account permissions and may allow code changes, CI/CD runs, access to private repositories, secrets, etc.

    The researchers note that, besides the permission restriction, which cannot be bypassed, an attacker also needs the target project’s path and ID.

    In public projects, this info is publicly available, while in private projects, the ID can be brute-forced, but the path would need to be leaked.

    GitLab warns in its documentation about the security implications of exposing these addresses, saying that they are private and “generated just for you.”

    “Keep it to yourself, because anyone who knows it can create issues or merge requests as if they were you. If you suspect this private email address was leaked, reset the token immediately,” GitLab warns.

    Exposed private email addresses

    In one afternoon, Aikido researchers found a dozen live GitLab incoming email addresses in public READMEs, contributing guides, and support pages.

    The researchers say that these addresses were deliberately included in public documentation to send bug reports to maintainers.

    In many cases, the exposure affected popular open-source projects, creating supply-chain risks for large user bases. “A few belonged to very popular open source projects,” the researchers say.

    Aikido says it reported the issue to GitLab through HackerOne in May, but GitLab closed it as “intended behavior.”

    The company followed up with a second notification in June, prompting GitLab to update its UI to mention merge requests, remove false statements about token data access, and document that incoming email bypasses IP restrictions.

    Project maintainers should stop voluntarily exposing that info in public documentation and reset tokens for projects they exposed this way in the past.


    article image

    Join Mikko Hyppönen and security leaders from the NFL, CHANEL, and Atlassian for a two-hour digital summit on what AI-speed attacks change, what defenders should stop doing, and how to validate, decide, fix, and re-validate at machine speed.

    Save your seat



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleThis ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans
    admin
    • Website

    Related Posts

    News

    This ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans

    September 24, 2026
    News

    Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

    September 24, 2026
    News

    Hackers now exploit critical Roundcube flaw in code injection attacks

    September 24, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202645 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    Woman Arrested, Dragged Away After Quietly Speaking About Flock at City Council Meeting

    September 23, 202645 Views

    How fraudsters target credit unions

    May 4, 202644 Views
    Our Picks

    Exposed GitLab project email addresses let attackers push code

    September 24, 2026

    This ‘World of Warcraft: Forever’ Mod Blocks All Interactions With Asmongold Fans

    September 24, 2026

    Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

    September 24, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.