A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
- ID
- 27816
- Status
- summarized
- Published
- 24 Sep 2026, 12:53 AM
- Fetched
- 24 Sep 2026, 2:16 AM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 8.0
- Created
- 24 Sep 2026, 2:17 AM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
GitLab's per-user 'email work item' address contains a non-expiring token that acts as a credential across every project your account can access. Aikido Security showed that anyone who obtains this address can change the suffix from -issue to -merge-request, attach a patch, name a target branch in the subject line, and GitLab will commit that code as you—even to main—and run CI/CD jobs if the patch modifies .gitlab-ci.yml. GitLab does not verify the sender of the email.
Why it matters
If you use GitLab, treat your issue-by-email address as a secret credential: it does not expire, is shared across all your projects, and a Maintainer-level leak gives an attacker access to protected branches and CI/CD secrets. Check where this address has appeared (logs, screenshots, forwarded emails, ticketing systems) and rotate it in GitLab settings immediately if it has been exposed.
Discussion angle
Walk through the attack chain live: show a GitLab issue-email address, demonstrate the -issue to -merge-request suffix swap, and discuss whether your team's CI/CD secret exposure would be catastrophic if a Maintainer's address leaked.