AI Weekly Malaysia

Back to items Summaries

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

ID
27816
Status
summarized
Published
24 Sep 2026, 12:53 AM
Fetched
24 Sep 2026, 2:16 AM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
8.0
Created
24 Sep 2026, 2:17 AM
Tags
Audience
developersvibe_coderssaas_founders

What happened

GitLab's per-user 'email work item' address contains a non-expiring token that acts as a credential across every project your account can access. Aikido Security showed that anyone who obtains this address can change the suffix from -issue to -merge-request, attach a patch, name a target branch in the subject line, and GitLab will commit that code as you—even to main—and run CI/CD jobs if the patch modifies .gitlab-ci.yml. GitLab does not verify the sender of the email.

Why it matters

If you use GitLab, treat your issue-by-email address as a secret credential: it does not expire, is shared across all your projects, and a Maintainer-level leak gives an attacker access to protected branches and CI/CD secrets. Check where this address has appeared (logs, screenshots, forwarded emails, ticketing systems) and rotate it in GitLab settings immediately if it has been exposed.

Discussion angle

Walk through the attack chain live: show a GitLab issue-email address, demonstrate the -issue to -merge-request suffix swap, and discuss whether your team's CI/CD secret exposure would be catastrophic if a Maintainer's address leaked.

Top