CyberSecurity News
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
AI summary
A security researcher has published a proof-of-concept exploit for a vulnerability in GitLab, allowing authenticated users to run commands as git on an unpatched self-managed server. The exploit involves committing two specially crafted Jupyter notebooks and requesting their diff, triggering the vulnerability. This can be done by an ordinary authenticated user without needing administrator rights or continuous integration runner access. The exploit does not require any interaction from the victim. The vulnerability is present in GitLab version 18.11.3.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

