HackerFeeds

CyberSecurity News

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The Hacker News
· September 23, 2026

AI summary

A private email address provided by GitLab for filing issues can be used as a credential to push code and run CI jobs in a user's name. This email address can be found behind a button labeled "Email work item to this project" and is used to open issues in a project. If someone obtains this email address, they can email a patch that GitLab will commit in the user's name to any branch the user has push access to. This includes the main branch, and the attacker can also start CI/CD jobs that run under the user's identity. The email address is intended to allow users to file issues by email, but it poses a security risk if it falls into the wrong hands.

Read the full article at The Hacker Newsthehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.